CVE-2019-20894: Traefik
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation where ERR_BAD_SSL_CLIENT_AUTH_CERT should have occurred.
Affected products
- Traefik Traefik: from 2.0.0, before 2.0.1 (fixed in 2.0.1)
Published 2020-07-02. Last modified 2026-06-17.