CVE-2026-85597
Traefik mTLS bypass - conflicting TLS options on routers sharing a hostname fall back to the default TLS config, dropping client-certificate authentication for every host in the rule (CVSS 8.2)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.0.0, < 2.11.55
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.11
- Fixed in
- Traefik 2.11.55
- Fixed in
- Traefik 3.7.11
- Added to NewScan
- 2026-09-04
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-04. GHSA-g55h-rg46-x9c5, same affected/patched pair as CVE-2026-85595 (`<= v2.11.54`, `>= v3.0.0 <= v3.7.10` -> v2.11.55 / v3.7.11), so the same two arms. Kept as its own CVE rather than folded into 85595's note because the two are different middleware paths (digest auth vs TLS option resolution) and an assessor keys remediation on the id; build_known_vuln_finding groups them into one finding per component anyway. NOT expressible as a probe: the bypass needs two conflicting router/Ingress definitions we cannot see from outside, so the version gate IS the detection.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-85597 (see the 2.x row). Shares the measurement in the CVE-2026-85595 3.x row: 3.7.10 inside, 3.7.11 outside.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →