CVE-2026-85596
Traefik Kubernetes Ingress NGINX provider mTLS bypass - Ingresses sharing a host and client CA generate distinct TLS option names, are read as a conflict, and fall back to a default with no client-certificate requirement (CVSS 8.2)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 3.7.0, < 3.7.11
- Fixed in
- Traefik 3.7.11
- Added to NewScan
- 2026-09-04
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-04. GHSA-j994-9gqj-9hwq, affected verbatim `>=v3.7.0, <=v3.7.10`, patched `v3.7.11` - ONE arm only, and deliberately narrower than CVE-2026-85597's 3.x arm even though both are TLS-option conflicts fixed in 3.7.11: the advisory states neither v2 nor v3.0-v3.6 is affected, because the nginx.ingress.kubernetes.io annotation path this travels only exists in the 3.7 Ingress NGINX provider. Widening it to ge 3.0.0 to match its sibling would assert a range the advisory denies.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →