Improper access control in Traefik - #VU144552
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass client-certificate authentication and access a protected backend.
The vulnerability exists due to improper access control in TLS options conflict resolution for multi-host routers when handling TLS handshakes for overlapping host rules with different TLS options. A remote attacker can connect to a protected hostname without a client certificate to bypass client-certificate authentication and access a protected backend.
The issue is limited to configurations where a multi-host router overlaps another router with a different TLS option for only one of its hostnames.