CVE-2026-85597: Traefik
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
Affected products
- Traefik Traefik: before 2.11.55 (fixed in 2.11.55); from 3.0.0, before 3.7.11 (fixed in 3.7.11)
Published 2026-09-04. Last modified 2026-10-08.