Authentication mechanism absence or evasion In github.com/traefik/traefik
Description
Traefik affected by TLS ClientAuth Bypass on HTTP/3
Summary
There is a potential vulnerability in Traefik managing HTTP/3 connections.
More details in the CVE-2025-68121.
Patches
Workarounds
No workaround
For more information
If you have any questions or comments about this advisory, please open an issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
go | 3.6.8 | ||
go | 2.0.0-alpha1+incompatible | ||
go | 2.11.37 |
Aliases
1. 2.
References
1.