Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53622

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 10
CVSS3: 9.1
EPSS Низкий

Описание

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of the configured hostname. Because the handshake falls back to the default TLS configuration — which may not require client certificates — a client can complete the QUIC handshake without presenting a certificate, while the subsequent HTTP routing layer still dispatches the request to a backend protected by a router-specific mTLS policy. The issue affects deployments where HTTP/3 is enabled, a router uses a wildcard Host rule or case-insensitive hostname matching, a router-specific TLSOptions enforces client cer

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия до 3.7.3 (исключая)

EPSS

Процентиль: 21%
0.00289
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-288
CWE-289

Связанные уязвимости

CVSS3: 9.1
redhat
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of the configured hostname. Because the handshake falls back to the default TLS configuration — which may not require client certificates — a client can complete the QUIC handshake without presenting a certificate, while the subsequent HTTP routing layer still dispatches the request to a backend protected by a router-specific mTLS policy. The issue affects deployments where HTTP/3 is enabled, a router uses a wildcard Host rule or case-insensitive hostname matching, a router-specific TLSOptions enforces client ...

CVSS3: 10
debian
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, th ...

github
около 2 месяцев назад

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

EPSS

Процентиль: 21%
0.00289
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-288
CWE-289