CVE-2026-32305 is a medium-severity vulnerability affecting Traefik versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1. It allows an attacker to bypass mutual TLS (mTLS) authentication by exploiting a flaw in Traefik's TLS SNI pre-sniffing logic when handling fragmented ClientHello packets, enabling unauthorized access to services that should require client certificates. With a CVSS score of 5.3, this network-exploitable vulnerability has low attack complexity and primarily impacts confidentiality by circumventing authentication. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.41CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | ||
>= 3.0.0, <= 3.6.11CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | ||
3.7.0CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:3.7.0:ea1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config
Mar 20, 2026Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config
Mar 20, 2026