Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85596— Traefik v3.7 Authentication Bypass via TLS Option Conflict

Quick assessment

Affected
traefik traefik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Traefik 版本 v3.7.0 至 v3.7.10 中的 Kubernetes Ingress NGINX 提供者存在一个认证绕过漏洞。 当 Ingress 资源带有 注解时,系统生成的 TLS 选项名称是基于该 Ingress 的命名空间(namespace)和名称(name)。因此,如果两个 Ingress 对象共享相同的主机名、相同的客户端 CA 密钥以及相同的客户端认证模式,它们会为同一主机生成两个不同的 TLS 选项名称。 Traefik 将此情况视为 TLS 选项冲突,并回退到入口点(entry p

CVSS 8.2 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
traefik traefik 3.7.0≤ 3.7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85596

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Traefik v3.7 Authentication Bypass via TLS Option Conflict
Source: CVE Program / CVE List V5
Vulnerability Description
Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a result, two Ingress objects sharing the same host, the same client CA secret, and the same client-authentication mode produced two distinct TLS option names for that host. Traefik treats this as a TLS options conflict and falls back to the entry point's default TLS configuration, which does not request a client certificate, so a route configured with nginx.ingress.kubernetes.io/auth-tls-verify-client: "on" becomes reachable without a client certificate. Only the v3.7 line is affected; the issue is fixed in v3.7.11.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
traefik traefik 3.7.0 ~ 3.7.12 -

II. Public POCs for CVE-2026-85596

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85596

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85596 (2)

Same Patch Batch · traefik · 2026-09-04 · 4 CVEs total

CVE-2026-85595 9.3 CRITICAL Traefik before v2.11.55 Authentication Bypass via digestAuth
CVE-2026-85597 8.2 HIGH Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict
CVE-2026-85594 7.0 HIGH Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

IV. Related Vulnerabilities

V. Comments for CVE-2026-85596

No comments yet


Leave a comment