Skip to content

[GHSA-q42x-32f8-m4r5] Traefik before v2.11.55 contains a TLS option conflict... - #9434

Open
james-yusuke wants to merge 1 commit into
james-yusuke/advisory-improvement-9434from
james-yusuke-GHSA-q42x-32f8-m4r5
Open

[GHSA-q42x-32f8-m4r5] Traefik before v2.11.55 contains a TLS option conflict...#9434
james-yusuke wants to merge 1 commit into
james-yusuke/advisory-improvement-9434from
james-yusuke-GHSA-q42x-32f8-m4r5

Conversation

@james-yusuke

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • Description
  • Summary

Comments
The published CVE-2026-85597 record contains an apparent inconsistency in its affected version metadata.

The CNA affected-version data lists Traefik v3.0.0 through v3.7.10 as affected, while the CPE applicability lists v3.0.0 through v3.7.12.

This suggestion does not assume that v3.7.11 or v3.7.12 are vulnerable. It is intended to flag the inconsistency so that the affected-version metadata can be reviewed and corrected based on the authoritative vendor/CNA information.

@github-actions
github-actions Bot changed the base branch from main to james-yusuke/advisory-improvement-9434 September 9, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant