VDB

GO-2026-4793

GO-2026-4793 PUBLISHED

Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config in github.com/traefik/traefik

Affected Products

VendorProductVersions
github.comtraefik/traefik/v30, 3.7.0-ea.1, 3.7.0-ea.1
github.comtraefik/traefik/v20, 0
github.comtraefik/traefik0, 0

Timeline

  • Mar 23, 2026 CVE Published
  • Apr 16, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›