CVE-2025-66491 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-s…
Medium CVSS: 5.9

CVE-2025-66491

Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backend TLS certificate verification) actually disables verification, allowing man-in-the-middle attacks against HTTPS backends when operators believe they are protected. This issue is fixed in version 3.6.3.
Vendor
Traefik
Product
Traefik
CWE
CWE-295
Yayın Tarihi
2025-12-09 01:16:55
Güncelleme
2026-01-02 21:12:07
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar