CVE-2026-53622
traefik traefik, Red Hat OpenShift Dev Spaces
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of the configured hostname. Because the handshake falls back to the default TLS configuration — which may not require c...
- CVSS
- 7.8
- EPSS
- 0.29% 21.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.24