Description
Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 04 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts. | |
| Title | Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict | |
| First Time appeared |
Traefik
Traefik traefik |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Traefik
Traefik traefik |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T11:30:00.783Z
Reserved: 2026-09-04T11:00:28.730Z
Link: CVE-2026-85597
No data.
Status : Received
Published: 2026-09-04T12:17:23.210
Modified: 2026-09-04T12:17:23.210
Link: CVE-2026-85597
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-863
Incorrect Authorization