← All CVEs NewScan detects
high

CVE-2026-85597

Traefik mTLS bypass - conflicting TLS options on routers sharing a hostname fall back to the default TLS config, dropping client-certificate authentication for every host in the rule (CVSS 8.2)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 2.0.0, < 2.11.55
Affected versions
Traefik ≥ 3.0.0, < 3.7.11
Fixed in
Traefik 2.11.55
Fixed in
Traefik 3.7.11
Added to NewScan
2026-09-04
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-04. GHSA-g55h-rg46-x9c5, same affected/patched pair as CVE-2026-85595 (`<= v2.11.54`, `>= v3.0.0 <= v3.7.10` -> v2.11.55 / v3.7.11), so the same two arms. Kept as its own CVE rather than folded into 85595's note because the two are different middleware paths (digest auth vs TLS option resolution) and an assessor keys remediation on the id; build_known_vuln_finding groups them into one finding per component anyway. NOT expressible as a probe: the bypass needs two conflicting router/Ingress definitions we cannot see from outside, so the version gate IS the detection.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-85597 (see the 2.x row). Shares the measurement in the CVE-2026-85595 3.x row: 3.7.10 inside, 3.7.11 outside.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →