CVE-2026-32305Disclosure(traefik / traefik)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Traefik's SNI extraction may fail with an EOF and return an empty SNI. The TCP router then falls back to the default TLS configuration, which does not require client certificates by default. This allows an attacker to bypass route-level mTLS enforcement and access services that should require mutual TLS authentication. This issue is patched in versions 2.11.41, 3.6.11 and 3.7.0-ea.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-1188CWE-179

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
traefik

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 103-2003-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32305 mTLS Bypass Vulnerability in Traefik via Fragmented TLS ClientHello Packets https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32305

    Post summary

    The text announces a newly disclosed mTLS bypass vulnerability in Traefik (CVE‑2026‑32305) that exploits fragmented ClientHello packets, providing technical details but no PoC, exploit code, or patch information.

    0000150
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32305 Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the T… https://www.cve.org/CVERecord?id=CVE-2026-32305

    Post summary

    The post announces that specific Traefik versions are vulnerable to an mTLS bypass, but it offers no PoC, exploit code, patch, or active exploitation evidence.

    00000103
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---
Apptraefiktraefik3.7.0--

Explore more