High [CVE-2026-85597] Authentication bypass via TLS option conflict
This high-severity Red Hat Linux advisory covers CVE-2026-85597 affecting Red Hat OpenShift Dev Spaces.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers.
Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts. A flaw was found in Traefik.
By creating conflicting Transport Layer Security (TLS) options on multi-host routers, attackers can exploit shared TLS resolution across multiple hostnames in a single router rule.
When shared router rules encompass multiple hostnames, conflicting TLS settings cause strict mTLS enforcement to regress to default configuration parameters across all associated endpoints.
Within Red Hat environments utilizing affected Traefik versions, an unauthenticated remote attacker can exploit this fallback behavior to bypass client-certificate authentication controls and access protected backend services without valid credentials. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Weakness: CWE-303. Affected Red Hat products: Red Hat OpenShift Dev Spaces.
Red Hat lists Red Hat OpenShift GitOps as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
- < 11.55
- < 0.0
- < 7.10
Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source
Mitigation checklist
- Separate multi-host router rules into dedicated single-host routers so each domain explicitly defines its required TLS options without inheritance conflicts. Alternatively, enforce client-certificate authentication at an upstream ingress controller or API gateway before traffic reaches the Traefik router.
Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.