← All CVEs NewScan detects
high

CVE-2026-85596

Traefik Kubernetes Ingress NGINX provider mTLS bypass - Ingresses sharing a host and client CA generate distinct TLS option names, are read as a conflict, and fall back to a default with no client-certificate requirement (CVSS 8.2)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 3.7.0, < 3.7.11
Fixed in
Traefik 3.7.11
Added to NewScan
2026-09-04
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-04. GHSA-j994-9gqj-9hwq, affected verbatim `>=v3.7.0, <=v3.7.10`, patched `v3.7.11` - ONE arm only, and deliberately narrower than CVE-2026-85597's 3.x arm even though both are TLS-option conflicts fixed in 3.7.11: the advisory states neither v2 nor v3.0-v3.6 is affected, because the nginx.ingress.kubernetes.io annotation path this travels only exists in the 3.7 Ingress NGINX provider. Widening it to ge 3.0.0 to match its sibling would assert a range the advisory denies.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →