Skip to content
VulniPulse
High7.5Red Hat Linux

High [CVE-2026-85597] Authentication bypass via TLS option conflict

This high-severity Red Hat Linux advisory covers CVE-2026-85597 affecting Red Hat OpenShift Dev Spaces.

CVE-2026-85597 Published Sep 4, 2026Updated by vendor Sep 4, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers.

Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts. A flaw was found in Traefik.

By creating conflicting Transport Layer Security (TLS) options on multi-host routers, attackers can exploit shared TLS resolution across multiple hostnames in a single router rule.

When shared router rules encompass multiple hostnames, conflicting TLS settings cause strict mTLS enforcement to regress to default configuration parameters across all associated endpoints.

Within Red Hat environments utilizing affected Traefik versions, an unauthenticated remote attacker can exploit this fallback behavior to bypass client-certificate authentication controls and access protected backend services without valid credentials. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Weakness: CWE-303. Affected Red Hat products: Red Hat OpenShift Dev Spaces.

Red Hat lists Red Hat OpenShift GitOps as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

Affected versions
  • < 11.55
  • < 0.0
  • < 7.10

Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Separate multi-host router rules into dedicated single-host routers so each domain explicitly defines its required TLS options without inheritance conflicts. Alternatively, enforce client-certificate authentication at an upstream ingress controller or API gateway before traffic reaches the Traefik router.

Official advisory · high-confidence parse· fetched 40 minutes ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.