Back

HIGH

Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict

Published Sep 4, 2026

Description

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.

Affected products

Remediation

Red Hat statement

A flaw was found in Traefik before v2.11.55 and v3.0.0 through v3.7.10, where multi-host router configurations fail to isolate TLS options. When shared router rules encompass multiple hostnames, conflicting TLS settings cause strict mTLS enforcement to regress to default configuration parameters across all associated endpoints. Within Red Hat environments utilizing affected Traefik versions, an unauthenticated remote attacker can exploit this fallback behavior to bypass client-certificate authentication controls and access protected backend services without valid credentials.

Red Hat mitigation

Separate multi-host router rules into dedicated single-host routers so each domain explicitly defines its required TLS options without inheritance conflicts. Alternatively, enforce client-certificate authentication at an upstream ingress controller or API gateway before traffic reaches the Traefik router.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 5, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 4, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity Important
Public date Sep 4, 2026