{"schema_version":"1.3.1","id":"GO-2026-4530","modified":"2026-02-23T18:23:15Z","published":"2026-02-23T18:23:15Z","aliases":["GHSA-gv8r-9rw9-9697"],"summary":"Traefik affected by TLS ClientAuth Bypass on HTTP/3 in github.com/traefik/traefik","details":"Traefik affected by TLS ClientAuth Bypass on HTTP/3 in github.com/traefik/traefik","affected":[{"package":{"name":"github.com/traefik/traefik","ecosystem":"Go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{}},{"package":{"name":"github.com/traefik/traefik/v2","ecosystem":"Go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.37"}]}],"ecosystem_specific":{}},{"package":{"name":"github.com/traefik/traefik/v3","ecosystem":"Go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.6.8"}]}],"ecosystem_specific":{}}],"references":[{"type":"ADVISORY","url":"https://github.com/traefik/traefik/security/advisories/GHSA-gv8r-9rw9-9697"}],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-4530","review_status":"UNREVIEWED"}}