Executive brief
Traefik, a popular open-source tool used to route and balance internet traffic, contains a security flaw that can allow unauthorized users to bypass identity checks. Specifically, when a service is configured to require a digital certificate from a user (mutual TLS), an attacker can use specially formatted network traffic to trick Traefik into skipping this requirement. This could allow an attacker to access private internal services or data that should have been protected by strict authentication.
Technical details
A vulnerability exists in Traefik's TLS SNI pre-sniffing logic. When a TLS ClientHello is fragmented across multiple records, the SNI extraction logic in the `ServeTCP` function may fail with an EOF, resulting in an empty SNI. Because the SNI is not correctly identified, the TCP router falls back to the default TLS configuration. If the default configuration does not require client certificates (the default 'NoClientCert' setting), the handshake succeeds without authentication, allowing the attacker to reach backends that were intended to be protected by 'RequireAndVerifyClientCert' policies. The issue is resolved in versions 2.11.41, 3.6.11, and 3.7.0-ea.2.
Affected products
- Traefik Labs Traefik <= 2.11.40, 3.0.0-beta1 through 3.6.10, 3.7.0-ea.1
Timeline
- 2026-03-18: patched: Version 2.11.41 released
- 2026-03-19: patched: Versions 3.6.11 and 3.7.0-ea.2 released
- 2026-03-20: advisory: GHSA-wvvq-wgcr-9q48 published
References
- https://github.com/traefik/traefik/releases/tag/v2.11.41
- https://github.com/traefik/traefik/releases/tag/v3.6.11
- https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.2
- https://github.com/traefik/traefik/security/advisories/GHSA-wvvq-wgcr-9q48
- https://access.redhat.com/errata/RHSA-2026:10175
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/security/cve/CVE-2026-32305