Skip to content

[GHSA-rgpg-cpwg-4f45] Traefik versions >= v3.7.0 and <= v3.7.10 contain an... - #9437

Open
james-yusuke wants to merge 1 commit into
james-yusuke/advisory-improvement-9437from
james-yusuke-GHSA-rgpg-cpwg-4f45
Open

[GHSA-rgpg-cpwg-4f45] Traefik versions >= v3.7.0 and <= v3.7.10 contain an...#9437
james-yusuke wants to merge 1 commit into
james-yusuke/advisory-improvement-9437from
james-yusuke-GHSA-rgpg-cpwg-4f45

Conversation

@james-yusuke

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v4
  • Description
  • Summary

Comments
This improvement clarifies the scope of CVE-2026-85596 and its relationship to the related but distinct CVE-2026-85597.

CVE-2026-85596 is specific to the Kubernetes Ingress NGINX provider and affects Traefik v3.7.0 through v3.7.10, while CVE-2026-85597 concerns the broader TLS option conflict resolution behavior.

The additional references also document that both issues were addressed in Traefik v3.7.11.

@github-actions
github-actions Bot changed the base branch from main to james-yusuke/advisory-improvement-9437 September 9, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant