Junglewise Threat Intelligence

CVE-2026-85597: Traefik TLS option conflict mTLS bypass

CVE-2026-85597 · Severity: critical · CVSS 9.1 · Published 2026-09-04

Vendors: Traefik Labs.

Executive brief

Traefik is an open-source reverse proxy and load balancer used to route and secure network traffic to backend applications. A vulnerability in how Traefik resolves conflicting TLS certificate options on multi-host routers allows attackers to bypass client certificate authentication (mTLS) requirements and reach protected backend services without a valid certificate. An unauthenticated attacker with network access to the proxy can exploit this by triggering a TLS option conflict through a specially crafted router configuration, granting unauthorized access to sensitive backend systems.

Technical details

The vulnerability stems from Traefik's TLS options conflict resolution mechanism. When multiple routers on the same entry point define different TLS options for overlapping hostnames, Traefik resolves the conflict by falling back to default (permissive) TLS options at the router level. For multi-host routers, this fallback is incorrectly applied to all hostnames in the rule, not just the conflicting ones. An attacker can exploit this by registering a second router that creates a TLS option conflict on one hostname of a multi-host router requiring client certificates, causing the entire multi-host router to drop its mTLS enforcement. The attack is unauthenticated and requires only network access to the entry point. Fixed in Traefik v2.11.55, v3.7.11, and later; earlier versions require upgrade to receive patches.

Affected products

  • Traefik Labs Traefik before v2.11.55, v3.0.0 through v3.7.10

Timeline

  • 2026-08-21: disclosed: GHSA-g55h-rg46-x9c5 published
  • 2026-09-04: advisory: CVE-2026-85597 published
  • 2026-09-04: patched: Patches released: v2.11.55 and v3.7.11

References