TLS Option Conflict Resolution Issue in Traefik by Containous
CVE-2026-85597

8.2HIGH

Key Information:

Vendor

Traefik

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85597?

Traefik prior to version 2.11.55 has a vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by exploiting a conflict in TLS options on multi-host routers. This issue arises from shared TLS resolution among multiple hostnames within a single router configuration, which can lead the mTLS requirement to revert to default settings, permitting unauthorized access to protected backend services.

Affected Version(s)

traefik 0 < 2.11.55

traefik 3.0.0 <= 3.7.12

traefik 2.11.55

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

james-yusuke
.