CVE-2026-26999
traefik traefik, Red Hat OpenShift Dev Spaces 3.27
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake read error occurs, the code attempts a second handshake with different connection parameters, silently ignoring the initial error. A remote unauthenticated client can exploit this by sending an incomplete TLS record and stopping further data tra...
- CVSS
- 7.5
- EPSS
- 0.54% 42.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.06