highCVSS 10Vulnerability
GHSA-gv8r-9rw9-9697
### Summary There is a potential vulnerability in Traefik managing HTTP/3 connections. More details in the [CVE-2025-68121](https://nvd.nist.gov/vuln/detail/CVE-2025-68121). ## Patches - https://github.com/traefik/traefik/releases/tag/v2.11.37 - https://github.com/traefik/traefik/releases/tag/v3.6.8 ## Workarounds No workaround ## For more information If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
Properties
- ghsa_id
- GHSA-gv8r-9rw9-9697
- summary
- Traefik affected by TLS ClientAuth Bypass on HTTP/3
- severity
- high
- cvss_score
- 10
- cve_id
- GHSA-gv8r-9rw9-9697
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-02-20T21:14:27Z
- source_url
- https://github.com/advisories/GHSA-gv8r-9rw9-9697
- ghsa_updated
- 2026-03-11T20:35:10Z
Related Entities (5)
AFFECTS (3)
→[Software]go/github.com/traefik/traefik
→[Software]go/github.com/traefik/traefik/v3
→[Software]go/github.com/traefik/traefik/v2
HAS_WEAKNESS (1)
→[Weakness]Dependency on Vulnerable Third-Party Component
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph