Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict
Published Sep 4, 2026
8.2
HIGHCVSS 4.0
EPSS 0.35%
Description
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
Affected products
-
- Version 0StatusaffectedConstraints<2.11.55
- Version 3.0.0StatusaffectedConstraints<=3.7.12
- Version 2.11.55StatusunaffectedConstraints-
- Version
No data.
Red Hat OpenShift Dev Spaces
devspaces/traefik-rhel9
Affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in Traefik before v2.11.55 and v3.0.0 through v3.7.10, where multi-host router configurations fail to isolate TLS options. When shared router rules encompass multiple hostnames, conflicting TLS settings cause strict mTLS enforcement to regress to default configuration parameters across all associated endpoints. Within Red Hat environments utilizing affected Traefik versions, an unauthenticated remote attacker can exploit this fallback behavior to bypass client-certificate authentication controls and access protected backend services without valid credentials.
Red Hat mitigation
Separate multi-host router rules into dedicated single-host routers so each domain explicitly defines its required TLS options without inheritance conflicts. Alternatively, enforce client-certificate authentication at an upstream ingress controller or API gateway before traffic reaches the Traefik router.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 4, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.35% (0.00351) | 26.48th | v5 (v2026.06.15) |
| Sep 5, 2026 | 0.23% (0.00230) | 13.69th | v5 (v2026.06.15) |
References (6)
- https://access.redhat.com/security/cve/CVE-2026-85597 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2528835 Issue Tracking
- https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 vendor-advisoryExploitMitigationPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85597
- https://www.cve.org/CVERecord?id=CVE-2026-85597
- https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-85597 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2528835 | Issue Tracking | |
| https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 | vendor-advisoryExploitMitigationPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-85597 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-85597 | ||
| https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.