{"id":"GO-2026-5152","summary":"Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik","details":"The SNICheck middleware in Traefik ignores wildcard TLSOptions mappings, allowing an unauthenticated attacker to bypass mTLS requirements by using a domain-fronted request. This occurs because the middleware compares the TLS options name used during the handshake with a pre-computed value that may not account for wildcard matches correctly when certain configuration models are applied.","aliases":["CVE-2026-48491","GHSA-5r4w-85f3-pw66"],"modified":"2026-08-11T20:33:01.906417877Z","published":"2026-08-11T20:19:48Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5152"},"references":[{"type":"ADVISORY","url":"https://github.com/traefik/traefik/security/advisories/GHSA-5r4w-85f3-pw66"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.7.3"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.6.19"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v2.11.48"}],"affected":[{"package":{"name":"github.com/traefik/traefik/v2","ecosystem":"Go","purl":"pkg:golang/github.com/traefik/traefik/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.48"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/traefik/traefik/v2/pkg/middlewares/snicheck","symbols":["SNICheck.ServeHTTP"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5152.json"}},{"package":{"name":"github.com/traefik/traefik/v3","ecosystem":"Go","purl":"pkg:golang/github.com/traefik/traefik/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.7.0"},{"fixed":"3.7.3"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/traefik/traefik/v3/pkg/middlewares/snicheck","symbols":["SNICheck.ServeHTTP"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5152.json"}}],"schema_version":"1.9.0"}