Improper Certificate Validation in Traefik - #VU153916
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.
The vulnerability exists due to improper certificate validation in the connection-scoped NTLM/Kerberos sticky round tripper when reusing a backend transport across services with different ServersTransport configurations. A remote attacker can send a request to one service followed by a request to another service on the same keep-alive connection to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.
The first service's backend must respond with a WWW-Authenticate: NTLM or Negotiate challenge. The reused transport applies the first service's TLS settings instead of the second service's configured root CAs, server name, and certificate verification settings.