CVE-2026-32305
Description
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Traefik's SNI extraction may fail with an EOF and return an empty SNI. The TCP router then falls back to the default TLS configuration, which does not require client certificates by default. This allows an attacker to bypass route-level mTLS enforcement and access services that should require mutual TLS authentication. This issue is patched in versions 2.11.41, 3.6.11 and 3.7.0-ea.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/traefik/traefik/v3Go | >= 3.7.0-ea.1, < 3.7.0-ea.2 | 3.7.0-ea.2 |
github.com/traefik/traefik/v3Go | < 3.6.11 | 3.6.11 |
github.com/traefik/traefik/v2Go | < 2.11.41 | 2.11.41 |
github.com/traefik/traefikGo | <= 1.7.34 | — |
Affected products
12- osv-coords9 versionspkg:apk/chainguard/traefik-3.5pkg:apk/wolfi/traefik-3.5pkg:golang/github.com/traefik/traefikpkg:golang/github.com/traefik/traefik/v2pkg:golang/github.com/traefik/traefik/v3pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/traefik&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/traefik2&distro=openSUSE%20Tumbleweed
< 3.5.6-r6+ 8 more
- (no CPE)range: < 3.5.6-r6
- (no CPE)range: < 3.5.6-r6
- (no CPE)range: <= 1.7.34
- (no CPE)range: < 2.11.41
- (no CPE)range: >= 3.7.0-ea.1, < 3.7.0-ea.2
- (no CPE)range: < 0.0.20260326T203309-150000.1.155.2
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 3.6.12-1.1
- (no CPE)range: < 2.11.42-1.1
Patches
Vulnerability mechanics
References
11- github.com/traefik/traefik/security/advisories/GHSA-wvvq-wgcr-9q48nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-wvvq-wgcr-9q48ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-32305ghsaADVISORY
- github.com/traefik/traefik/releases/tag/v2.11.41nvdRelease NotesWEB
- github.com/traefik/traefik/releases/tag/v3.6.11nvdRelease NotesWEB
- github.com/traefik/traefik/releases/tag/v3.7.0-ea.2nvdRelease NotesWEB
- access.redhat.com/errata/RHSA-2026:10175nvd
- access.redhat.com/errata/RHSA-2026:21772nvd
- access.redhat.com/security/cve/CVE-2026-32305nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32305.jsonnvd
News mentions
0No linked articles in our index yet.