Improper Authentication in Traefik - #VU153911
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a host's client certificate authentication.
The vulnerability exists due to improper authentication caused by TLS option name collisions in the Kubernetes Ingress NGINX provider when generating TLS options for Ingresses using the nginx.ingress.kubernetes.io/auth-tls-secret annotation. A remote attacker can present a client certificate issued by another host's certificate authority to bypass a host's client certificate authentication.
Exploitation requires resource names that collide when dots are replaced with dashes. The Ingress processed second reuses the TLS option generated for the first, causing its legitimate client certificates to be refused.