Database/Container, Kubernetes & orchestration
Traefik: mTLS bypass via SNI pre-sniffing on fragmented ClientHello packets
CVSS 7.8CVE-2026-32305Container, Kubernetes & orchestrationcurated
Impact
mTLS bypass via SNI pre-sniffing on fragmented ClientHello packets
Who can reach it
Unauthenticated network
What to do
Rolling Traefik upgrade
References
Related entries
- Traefik: Authentication bypass in ForwardAuth when trustForwardHeader=falseCVE-2026-35051 · TraefikHigh
- Traefik: Authentication bypass in ForwardAuth and snippet-based auth middlewareCVE-2026-39858 · TraefikHigh
- Traefik: Authentication bypass via StripPrefixRegex middlewareCVE-2026-40912 · TraefikHigh
- Traefik: StripPrefix middleware allows route-level authentication bypassCVE-2026-48020 · TraefikHigh
- Traefik: HTTP/3 QUIC TLS configuration selection lets clients bypass router-specific mTLS enforcementCVE-2026-53622 · TraefikHigh
- Traefik: Authentication bypass via path traversal in ReplacePathRegexCVE-2026-65600 · TraefikHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.