CVE-2026-85597
EUVD-2026-7102004.09.2026, 12:17
Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| traefik | traefik | 𝑥 < 2.11.55 | CNA |
| traefik | traefik | 3.0.0 ≤ 𝑥 ≤ 3.7.12 | CNA |