{"id":"CVE-2026-85597","title":"Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…","summary":"Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-863","CWE-303"],"vendor":"traefik","product":"traefik","affected":["traefik < 2.11.55","traefik >= 3.0.0, < 3.7.11"],"patched":["traefik 3.7.11"],"published":"2026-09-04","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:42:21.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85597","references":[{"url":"https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85597.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-85597"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2528835"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-85597"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85597"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00205,"epssPercentile":0.10763,"scores":{"nvd":9.1,"vendor":7.5},"ingestedAt":"2026-09-06T01:47:57.962Z","slug":"CVE-2026-85597","body":"## Overview\n\nTraefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.\n\n## Affected\n\n- `traefik < 2.11.55`\n- `traefik >= 3.0.0, < 3.7.11`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `traefik 3.7.11`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Dev Spaces · no fix planned: Red Hat OpenShift Dev Spaces · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85597.json)","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":205766,"id":"CVE-2026-85597","ts":1789592771955,"field":"cvss","old":"7.5","new":"9.1"},{"seq":205765,"id":"CVE-2026-85597","ts":1789592771955,"field":"severity","old":"high","new":"critical"},{"seq":202047,"id":"CVE-2026-85597","ts":1789400046767,"field":"cvss","old":null,"new":"7.5"},{"seq":202046,"id":"CVE-2026-85597","ts":1789400046767,"field":"severity","old":"none","new":"high"},{"seq":200774,"id":"CVE-2026-85597","ts":1789397615313,"field":"cvss","old":"7.5","new":null},{"seq":200773,"id":"CVE-2026-85597","ts":1789397615313,"field":"severity","old":"high","new":"none"},{"seq":199467,"id":"CVE-2026-85597","ts":1789395514391,"field":"cvss","old":null,"new":"7.5"},{"seq":199466,"id":"CVE-2026-85597","ts":1789395514391,"field":"severity","old":"none","new":"high"},{"seq":198712,"id":"CVE-2026-85597","ts":1789392242868,"field":"cvss","old":"7.5","new":null},{"seq":198711,"id":"CVE-2026-85597","ts":1789392242868,"field":"severity","old":"high","new":"none"},{"seq":197045,"id":"CVE-2026-85597","ts":1789384291229,"field":"cvss","old":null,"new":"7.5"},{"seq":197044,"id":"CVE-2026-85597","ts":1789384291229,"field":"severity","old":"none","new":"high"},{"seq":194174,"id":"CVE-2026-85597","ts":1789378782000,"field":"cvss","old":"7.5","new":null},{"seq":194173,"id":"CVE-2026-85597","ts":1789378782000,"field":"severity","old":"high","new":"none"},{"seq":192961,"id":"CVE-2026-85597","ts":1789376513803,"field":"cvss","old":null,"new":"7.5"},{"seq":192960,"id":"CVE-2026-85597","ts":1789376513803,"field":"severity","old":"none","new":"high"},{"seq":191748,"id":"CVE-2026-85597","ts":1789373630023,"field":"cvss","old":"7.5","new":null},{"seq":191747,"id":"CVE-2026-85597","ts":1789373630023,"field":"severity","old":"high","new":"none"},{"seq":190533,"id":"CVE-2026-85597","ts":1789369472750,"field":"cvss","old":null,"new":"7.5"},{"seq":190532,"id":"CVE-2026-85597","ts":1789369472750,"field":"severity","old":"none","new":"high"},{"seq":189320,"id":"CVE-2026-85597","ts":1789368407930,"field":"cvss","old":"7.5","new":null},{"seq":189319,"id":"CVE-2026-85597","ts":1789368407930,"field":"severity","old":"high","new":"none"},{"seq":188103,"id":"CVE-2026-85597","ts":1789365229438,"field":"cvss","old":null,"new":"7.5"},{"seq":188102,"id":"CVE-2026-85597","ts":1789365229438,"field":"severity","old":"none","new":"high"},{"seq":186890,"id":"CVE-2026-85597","ts":1789363470220,"field":"cvss","old":"7.5","new":null},{"seq":186889,"id":"CVE-2026-85597","ts":1789363470220,"field":"severity","old":"high","new":"none"},{"seq":185676,"id":"CVE-2026-85597","ts":1789361227715,"field":"cvss","old":null,"new":"7.5"},{"seq":185675,"id":"CVE-2026-85597","ts":1789361227715,"field":"severity","old":"none","new":"high"},{"seq":184463,"id":"CVE-2026-85597","ts":1789358362540,"field":"cvss","old":"7.5","new":null},{"seq":184462,"id":"CVE-2026-85597","ts":1789358362540,"field":"severity","old":"high","new":"none"},{"seq":182714,"id":"CVE-2026-85597","ts":1789354315848,"field":"cvss","old":null,"new":"7.5"},{"seq":182713,"id":"CVE-2026-85597","ts":1789354315848,"field":"severity","old":"none","new":"high"},{"seq":181507,"id":"CVE-2026-85597","ts":1789353316599,"field":"cvss","old":"7.5","new":null},{"seq":181506,"id":"CVE-2026-85597","ts":1789353316599,"field":"severity","old":"high","new":"none"},{"seq":180300,"id":"CVE-2026-85597","ts":1789350283494,"field":"cvss","old":null,"new":"7.5"},{"seq":180299,"id":"CVE-2026-85597","ts":1789350283494,"field":"severity","old":"none","new":"high"},{"seq":179093,"id":"CVE-2026-85597","ts":1789348291798,"field":"cvss","old":"7.5","new":null},{"seq":179092,"id":"CVE-2026-85597","ts":1789348291798,"field":"severity","old":"high","new":"none"},{"seq":177886,"id":"CVE-2026-85597","ts":1789346368780,"field":"cvss","old":null,"new":"7.5"},{"seq":177885,"id":"CVE-2026-85597","ts":1789346368780,"field":"severity","old":"none","new":"high"},{"seq":176679,"id":"CVE-2026-85597","ts":1789343183435,"field":"cvss","old":"7.5","new":null},{"seq":176678,"id":"CVE-2026-85597","ts":1789343183435,"field":"severity","old":"high","new":"none"},{"seq":174796,"id":"CVE-2026-85597","ts":1789334874419,"field":"cvss","old":null,"new":"7.5"},{"seq":174795,"id":"CVE-2026-85597","ts":1789334874419,"field":"severity","old":"none","new":"high"},{"seq":173591,"id":"CVE-2026-85597","ts":1789333685680,"field":"cvss","old":"7.5","new":null},{"seq":173590,"id":"CVE-2026-85597","ts":1789333685680,"field":"severity","old":"high","new":"none"},{"seq":172405,"id":"CVE-2026-85597","ts":1789331091777,"field":"cvss","old":null,"new":"7.5"},{"seq":172404,"id":"CVE-2026-85597","ts":1789331091777,"field":"severity","old":"none","new":"high"},{"seq":171219,"id":"CVE-2026-85597","ts":1789328779799,"field":"cvss","old":"7.5","new":null},{"seq":171218,"id":"CVE-2026-85597","ts":1789328779799,"field":"severity","old":"high","new":"none"}]}