CVE-2026-85597: Traefik

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.

Affected products

  • Traefik Traefik: before 2.11.55 (fixed in 2.11.55); from 3.0.0, before 3.7.11 (fixed in 3.7.11)

Published 2026-09-04. Last modified 2026-10-08.