Authentication Bypass Using an Alternate Path or Channel Affecting github.com/traefik/traefik/pkg/server package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.63% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMTRAEFIKTRAEFIKPKGSERVER-17675559
  • published29 Jun 2026
  • disclosed16 Jun 2026
  • creditkamil-sawicki

Introduced: 16 Jun 2026

CVE-2026-53622  (opens in a new tab)
CWE-288  (opens in a new tab)

How to fix?

There is no fixed version for github.com/traefik/traefik/pkg/server.

Overview

Affected versions of this package are vulnerable to Authentication Bypass Using an Alternate Path or Channel in the TLS configuration selection process for HTTP/3 connections, where an exact, case-sensitive lookup on the SNI value fails to match wildcard or mixed-case hostnames. An attacker can gain unauthorized access to protected backend services by connecting via HTTP/3 with a crafted SNI value that bypasses client certificate enforcement. This is only exploitable if HTTP/3 is enabled on the entrypoint, a router-specific configuration enforces client certificate authentication, the default TLS configuration does not require client certificates, and UDP access to the entrypoint is reachable by the attacker.

Workaround

This vulnerability can be mitigated by disabling HTTP/3 on entrypoints that rely on router-specific client certificate authentication, enforcing client authentication in the default TLS options, blocking UDP access to the HTTP/3 entrypoint, or enforcing client authentication at an additional layer behind the affected service.

CVSS Base Scores

version 4.0
version 3.1