CVE detail
CVE-2026-32305
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Traefik's SNI extraction may fail with an EOF and return an empty SNI. The TCP router then falls back to the default TLS configuration, which does not require client certificates by default. This allows an attacker to bypass route-level mTLS enforcement and access services that should require mutual TLS authentication. This issue is patched in versions 2.11.41, 3.6.11 and 3.7.0-ea.2.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32305.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 20, 2026, 11:18 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2449595bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 20, 2026, 11:18 AM - https://access.redhat.com/security/cve/CVE-2026-32305access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 20, 2026, 11:18 AM - https://access.redhat.com/errata/RHSA-2026:21772access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 20, 2026, 11:18 AM - https://access.redhat.com/errata/RHSA-2026:10175access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMar 20, 2026, 11:18 AM No excerpt available.
Exploitgithub.comMar 20, 2026, 11:18 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 11:18 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 11:18 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 11:18 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-41679CVSS 10.0 · Critical
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remot…
- CVE-2022-41648CVSS 9.2 · Critical
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enab…
- CVE-2020-8828CVSS 8.8 · High
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation…
- CVE-2018-15598CVSS 7.5 · High
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
- CVE-2026-63238CVSS 6.5 · Medium
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUI…
- CVE-2026-13690CVSS 7.4 · High
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's…