If you have any questions or comm...
id: GO-ID-PENDING
modules:
- module: github.com/traefik/traefik
non_go_versions:
- introduced: TODO (earliest fixed "3.6.3", vuln range ">= 3.5.0, <= 3.6.2")
vulnerable_at: 1.7.34
- module: github.com/traefik/traefik/v2
vulnerable_at: 2.11.32
- module: github.com/traefik/traefik/v3
vulnerable_at: 3.6.4
summary: Traefik Inverted TLS Verification Logic in ingress-nginx Provider in github.com/traefik/traefik
cves:
- CVE-2025-66491
ghsas:
- GHSA-7vww-mvcr-x6vj
references:
- advisory: https://github.com/advisories/GHSA-7vww-mvcr-x6vj
- advisory: https://github.com/traefik/traefik/security/advisories/GHSA-7vww-mvcr-x6vj
- fix: https://github.com/traefik/traefik/commit/14a1aedf5704673d875d210d7bacf103a43c77e4
- web: https://github.com/traefik/traefik/releases/tag/v3.6.3
source:
id: GHSA-7vww-mvcr-x6vj
created: 2025-12-08T17:01:15.106739496Z
review_status: UNREVIEWED
Advisory GHSA-7vww-mvcr-x6vj references a vulnerability in the following Go modules:
Description:
Impact
There is a potential vulnerability in Traefik NGINX provider managing the
nginx.ingress.kubernetes.io/proxy-ssl-verifyannotation.The provider inverts the semantics of the
nginx.ingress.kubernetes.io/proxy-ssl-verifyannotation. Setting the annotation to"on"(intending to enable backend TLS certificate verification) actually disables verification, allowing man-in-the-middle attacks against HTTPS backends when operators believe they are protected.Patches
For more information
If you have any questions or comm...
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.