Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85597— Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict

Quick assessment

Affected
traefik traefik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Traefik 在 v2.11.55 之前存在一个 TLS 选项冲突解决漏洞。该漏洞允许未认证的攻击者通过在多主机路由器上创建相互冲突的 TLS 选项,从而绕过客户端证书(client-certificate)认证。攻击者可以利用单个路由器规则中多个主机名之间共享的 TLS 解析机制,使严格的 mTLS(双向 TLS)要求回退到默认选项,进而访问受保护的后端服务。

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1598 · Phishing for Information

Affected Version Matrix 3

VendorProduct Version RangeStatus
traefik traefik < 2.11.55 affected
2.11.55 unaffected
3.0.0≤ 3.7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict
Source: CVE Program / CVE List V5
Vulnerability Description
Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
traefik traefik 0 ~ 2.11.55 -
traefik traefik 3.0.0 ~ 3.7.12 -

II. Public POCs for CVE-2026-85597

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85597

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85597 (2)

Same Patch Batch · traefik · 2026-09-04 · 4 CVEs total

CVE-2026-85595 9.3 CRITICAL Traefik before v2.11.55 Authentication Bypass via digestAuth
CVE-2026-85596 8.2 HIGH Traefik v3.7 Authentication Bypass via TLS Option Conflict
CVE-2026-85594 7.0 HIGH Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

IV. Related Vulnerabilities

V. Comments for CVE-2026-85597

No comments yet


Leave a comment