Not Failing Securely ('Failing Open') in Traefik - #VU153908

 

Not Failing Securely ('Failing Open') in Traefik - #VU153908

Published: October 7, 2026


Vulnerability identifier: #VU153908
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-636
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass router TLS requirements and access services without presenting a required client certificate.

The vulnerability exists due to a fail-open SNI check in Traefik's snicheck component when processing requests with missing TLS connection state. A remote attacker can send an HTTP/2 request with the :scheme http pseudo-header over a TLS connection to bypass router TLS requirements and access services without presenting a required client certificate.

Exposure requires a Traefik build made with Go 1.27. Exploitation depends on the target router having different TLS options from those negotiated for the connection.


Affected software

Traefik

Remediation

Install security update from vendor's website.

Traefik - addressed in versions 2.11.58, 3.7.14

External References

Related Security Bulletins