<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:46:46 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0690 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0690</link>
      <description>certfr-2026-avi-0690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0690</guid>
    </item>
    <item>
      <title>EUVD-2026-362916</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362916</link>
      <description>EUVD-2026-362916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362916</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48491</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48491</link>
      <description>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik&amp;#39;s domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik&amp;#39;s domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48491</guid>
    </item>
    <item>
      <title>GHSA-5r4w-85f3-pw66 — Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5r4w-85f3-pw66</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high severity vulnerability in Traefik&amp;#39;s domain-fronting protection (`SNICheck`) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router `TLSOptions`. When a router uses a wildcard host rule such as `Host(`*.example.com`)` with stricter TLS options (for example `RequireAndVerifyClientCert`), `SNICheck` resolves the TLS options for the HTTP `Host` header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP `Host` header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v3.7.3&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s `SNICheck` domain-fronting protection ignores wildcard `TLSOptions` mappings. A wildcard router such as `Host(&amp;#34;*.example.com&amp;#34;)` can require mTLS for direct access, but an unauthenticated client can complete the TLS handshake with another permissive SNI on the same entrypoint and then send `Host: api.example.com` / HTTP request authority `api.example.com` to reach the wildcard-prote…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high severity vulnerability in Traefik&amp;#39;s domain-fronting protection (`SNICheck`) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router `TLSOptions`. When a router uses a wildcard host rule such as `Host(`*.example.com`)` with stricter TLS options (for example `RequireAndVerifyClientCert`), `SNICheck` resolves the TLS options for the HTTP `Host` header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP `Host` header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v3.7.3&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s `SNICheck` domain-fronting protection ignores wildcard `TLSOptions` mappings. A wildcard router such as `Host(&amp;#34;*.example.com&amp;#34;)` can require mTLS for direct access, but an unauthenticated client can complete the TLS handshake with another permissive SNI on the same entrypoint and then send `Host: api.example.com` / HTTP request authority `api.example.com` to reach the wildcard-prote…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5r4w-85f3-pw66</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11047-1 — traefik-3.7.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11047-1</link>
      <description>&lt;p&gt;traefik-3.7.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;traefik-3.7.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11047-1</guid>
    </item>
    <item>
      <title>RHSA-2026:62260 — Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.0 Release.</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:62260</link>
      <description>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability curl: curl: Insecure connection establishment due to TLS configuration mismatch shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators curl: curl: Man-in-the-middle attack via SSH host key bypass org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/cryp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability curl: curl: Insecure connection establishment due to TLS configuration mismatch shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators curl: curl: Man-in-the-middle attack via SSH host key bypass org.eclipse.parsson/parsson: Eclipse Parsson: Denial of Service via uncontrolled resource consumption in JSON parsing jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections form-data: form-data: Form field override via CRLF injection undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object net/mail: golang: Go net/mail: Denial of Service via crafted email inputs golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/cryp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:62260</guid>
    </item>
  </channel>
</rss>
