Improper Certificate Validation in Traefik - #VU153916

 

Improper Certificate Validation in Traefik - #VU153916

Published: October 7, 2026


Vulnerability identifier: #VU153916
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.

The vulnerability exists due to improper certificate validation in the connection-scoped NTLM/Kerberos sticky round tripper when reusing a backend transport across services with different ServersTransport configurations. A remote attacker can send a request to one service followed by a request to another service on the same keep-alive connection to bypass backend TLS policies and cause one service's client certificate to be presented to another service's backend.

The first service's backend must respond with a WWW-Authenticate: NTLM or Negotiate challenge. The reused transport applies the first service's TLS settings instead of the second service's configured root CAs, server name, and certificate verification settings.


Affected software

Traefik

Remediation

Install security update from vendor's website.

Traefik - addressed in versions 2.11.58, 3.7.14

External References

Related Security Bulletins