CVE-2026-48491
Last modified
CVE-2026-48491 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Traefik | Traefik | >= 3.7.0, < 3.7.3 |
References
- https://github.com/traefik/traefik/releases/tag/v3.7.3Patch, Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-5r4w-85f3-pw66Exploit, Mailing List, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-48491?
How severe is CVE-2026-48491?
How do I fix CVE-2026-48491?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48486Signum Node is a HDD-mined cryptocurrency using an energy ef…7.5
- CVE-2026-48487Zeroconf is a pure Python implementation of multicast DNS se…5.3
- CVE-2026-48488phpMyFAQ is an open source FAQ web application. Prior to ver…2.7
- CVE-2026-48489Symfony is a PHP framework for web and console applications …7.5
- CVE-2026-4849A vulnerability was identified in code-projects Simple Laund…6.1
- CVE-2026-48490ArduinoCore-avr contains the source code and configuration f…6.9
- CVE-2026-48492Snipe-IT is an IT asset/license management system. Prior to …6.5
- CVE-2026-48493Snipe-IT is an IT asset/license management system. In versio…5.5
- CVE-2026-48494TypeBot is a chatbot builder tool. In version 3.16.1, an aut…7.1
- CVE-2026-48495TypeBot is a chatbot builder tool. Prior to version 3.17.0, …7.1
- CVE-2026-48496OpenTelemetry eBPF Profiler is a production-scale agent for …6.2
- CVE-2026-48497Envoy is an open source edge and service proxy designed for …7.5
Are you affected by CVE-2026-48491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
