CVE-2026-85597Critical· 9.1▾ MidnightTraefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
— → 7.5
none → high
7.5 → —
high → none
— → 7.5
none → high
7.5 → —
high → none
— → 7.5
none → high
Last analysed / modified upstream
7.5 → 9.1
high → critical
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
traefik < 2.11.55traefik >= 3.0.0, < 3.7.11Upgrade past the affected range:
traefik 3.7.11Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71325Medium· 4.4Traefik is an open-source edge router that makes publishing services a fun and easy experience
CVE-2026-88877Critical· 9.8Traefik is a HTTP reverse proxy and load balancer
CVE-2026-88878Medium· 5.3Traefik is an HTTP reverse proxy and load balancer
CVE-2026-88879High· 8.2Traefik is an HTTP reverse proxy and load balancer
CVE-2026-85594Critical· 9.8Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider
CVE-2026-85596Critical· 9.8Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider