CVE-2026-48491
Last modified
CVE-2026-48491 is a critical-severity vulnerability rated 10/10 on the CVSS scale. Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Traefik | Traefik | >= 3.7.0, < 3.7.3 |
References
- https://github.com/traefik/traefik/releases/tag/v3.7.3Patch, Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-5r4w-85f3-pw66Exploit, Mailing List, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-48491?
How severe is CVE-2026-48491?
How do I fix CVE-2026-48491?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48483TypeBot is a chatbot builder tool. Prior to version 3.17.0, …5.4
- CVE-2026-48485Quest Bot is an opensource Discord Bot. Prior to version 1.1…2.1
- CVE-2026-48487Zeroconf is a pure Python implementation of multicast DNS se…5.3
- CVE-2026-48488phpMyFAQ is an open source FAQ web application. Prior to ver…2.7
- CVE-2026-48489Symfony is a PHP framework for web and console applications …7.5
- CVE-2026-4849A vulnerability was identified in code-projects Simple Laund…6.1
- CVE-2026-48492Snipe-IT is an IT asset/license management system. Prior to …6.5
- CVE-2026-48493Snipe-IT is an IT asset/license management system. In versio…5.5
- CVE-2026-48494TypeBot is a chatbot builder tool. In version 3.16.1, an aut…7.1
- CVE-2026-48495TypeBot is a chatbot builder tool. Prior to version 3.17.0, …7.1
- CVE-2026-48497Envoy is an open source edge and service proxy designed for …7.5
- CVE-2026-48499Activepieces is an open source AI workflow automation platfo…9.3
Are you affected by CVE-2026-48491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
