PT-2025-49685 · Traefik+1 · Traefik+1

Published

2025-12-08

·

Updated

2026-01-08

·

CVE-2025-66491

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Traefik versions 3.5.0 through 3.6.2
Description Traefik is an HTTP reverse proxy and load balancer. A flaw exists in the TLS verification logic within the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. When this annotation is set to "on" with the intention of enabling backend TLS certificate verification, it inadvertently disables verification. This creates a potential for man-in-the-middle attacks against HTTPS backends, particularly when operators assume their connections are secured.
Recommendations Upgrade to Traefik version 3.6.3 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66491
GHSA-7VWW-MVCR-X6VJ
GO-2025-4205
OPENSUSE-SU-2026:10020-1
SUSE-SU-2026:0037-1

Affected Products

Alt Linux
Traefik