TLS Option Conflict Resolution Issue in Traefik by Containous
CVE-2026-85597
8.2HIGH
What is CVE-2026-85597?
Traefik prior to version 2.11.55 has a vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by exploiting a conflict in TLS options on multi-host routers. This issue arises from shared TLS resolution among multiple hostnames within a single router configuration, which can lead the mTLS requirement to revert to default settings, permitting unauthorized access to protected backend services.
Affected Version(s)
traefik 0 < 2.11.55
traefik 3.0.0 <= 3.7.12
traefik 2.11.55
