SB20261007232 - Multiple vulnerabilities in Traefik
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Not Failing Securely ('Failing Open') (CVE-ID: N/A)
CWE-ID: CWE-636 - Not Failing Securely (\'Failing Open\')
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass router TLS requirements and access services without presenting a required client certificate.
The vulnerability exists due to a fail-open SNI check in Traefik's snicheck component when processing requests with missing TLS connection state. A remote attacker can send an HTTP/2 request with the :scheme http pseudo-header over a TLS connection to bypass router TLS requirements and access services without presenting a required client certificate.
Exposure requires a Traefik build made with Go 1.27. Exploitation depends on the target router having different TLS options from those negotiated for the connection.
2) Missing Authentication for Critical Function (CVE-ID: N/A)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and source allow-list restrictions to access a protected backend.
The vulnerability exists due to missing authentication and source allow-list enforcement in the Kubernetes Ingress NGINX provider's sibling HTTP router when generating routing configuration for non-TLS entry points. A remote attacker can send an HTTP request with the Ingress host to a non-TLS entry point to bypass authentication and source allow-list restrictions to access a protected backend.
The Ingress must have the nginx.ingress.kubernetes.io/ssl-passthrough annotation set to true and access-control annotations such as auth-type with auth-secret, auth-url, or whitelist-source-range.
3) Exposure of Data Element to Wrong Session (CVE-ID: N/A)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read victim-only data and perform actions in the victim's name without presenting credentials.
The vulnerability exists due to improper isolation of connection-bound authentication identities in the FastProxy backend connection pool when dispatching requests to plain HTTP backends using NTLM or Negotiate authentication. A remote attacker can send requests through a new frontend connection that reuses a backend connection on which a victim has already authenticated to read victim-only data and perform actions in the victim's name without presenting credentials.
Exploitation requires experimental.fastProxy to be enabled and backend keep-alive to be in use. The default proxy implementation is not affected.
4) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a host's client certificate authentication.
The vulnerability exists due to improper authentication caused by TLS option name collisions in the Kubernetes Ingress NGINX provider when generating TLS options for Ingresses using the nginx.ingress.kubernetes.io/auth-tls-secret annotation. A remote attacker can present a client certificate issued by another host's certificate authority to bypass a host's client certificate authentication.
Exploitation requires resource names that collide when dots are replaced with dashes. The Ingress processed second reuses the TLS option generated for the first, causing its legitimate client certificates to be refused.
5) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to impersonate a legitimate client and perform reads or writes with that client's permissions.
The vulnerability exists due to improper authentication isolation in Traefik's globally shared backend connection pool when reusing authenticated backend connections. A remote attacker can send requests over a separate frontend connection that is assigned a victim-authenticated backend socket to impersonate a legitimate client and perform reads or writes with that client's permissions.
Exploitation requires a connection-bound NTLM or SPNEGO/Kerberos Negotiate backend and a legitimate client that sends a valid Authorization: Negotiate token on its first request. The ordinary challenge-first authentication flow is not affected. The issue occurs on HTTP/1.1 and HTTP/2 frontend connections.
6) Authentication Bypass by Spoofing (CVE-ID: N/A)
CWE-ID: CWE-290 - Authentication Bypass by Spoofing
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to impersonate a client certificate identity and bypass backend authentication.
The vulnerability exists due to improper verification of client identity headers in Traefik's Kubernetes Ingress-NGINX provider when handling plaintext HTTP requests for an Ingress configured to forward client certificate information upstream. A remote attacker can send forged Ssl-Client-* headers, including Ssl-Client-Verify: SUCCESS and a chosen certificate subject and issuer, to impersonate a client certificate identity and bypass backend authentication.
Exploitation requires the nginx.ingress.kubernetes.io/auth-tls-pass-certificate-to-upstream annotation, nginx.ingress.kubernetes.io/ssl-redirect set to "false", and a backend that trusts these headers as an mTLS identity. No client certificate needs to be presented. The identity-header middleware is attached only to the TLS router, not the plaintext HTTP router.
7) Race condition (CVE-ID: N/A)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper synchronization of shared reads and writes in Traefik's per-connection sticky round tripper when handling concurrent HTTP/2 or HTTP/3 requests over a single client connection. A remote attacker can send concurrent requests that race on the shared round tripper slot to cause a denial of service.
Exploitation requires a backend that responds with a WWW-Authenticate: NTLM or Negotiate challenge.
8) Improper Certificate Validation (CVE-ID: N/A)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.
The vulnerability exists due to improper certificate validation in the connection-scoped NTLM/Kerberos sticky round tripper when reusing a backend transport across services with different ServersTransport configurations. A remote attacker can send a request to one service followed by a request to another service on the same keep-alive connection to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.
The first service's backend must respond with a WWW-Authenticate: NTLM or Negotiate challenge. The reused transport applies the first service's TLS settings instead of the second service's configured root CAs, server name, and certificate verification settings.
Remediation
Install update from vendor's website.
References
- https://github.com/traefik/traefik/security/advisories/GHSA-fh26-gfpp-7xxx
- https://github.com/traefik/traefik/security/advisories/GHSA-qvj7-gq9c-hp7q
- https://github.com/traefik/traefik/security/advisories/GHSA-53qr-784g-cj35
- https://github.com/traefik/traefik/security/advisories/GHSA-rv2h-qh7j-xrjw
- https://github.com/traefik/traefik/security/advisories/GHSA-qm9f-w54v-q2qh
- https://github.com/traefik/traefik/security/advisories/GHSA-mwrr-6hp4-pxr6
- https://github.com/traefik/traefik/security/advisories/GHSA-mhjw-hmjv-p99x
- https://github.com/traefik/traefik/security/advisories/GHSA-cw35-4q88-3rmp