{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48491.json"
      }
    ],
    "title": "Traefik: Traefik: Unauthorized access due to mutual TLS bypass",
    "tracking": {
      "current_release_date": "2026-06-30T03:48:30+00:00",
      "generator": {
        "date": "2026-06-30T03:48:30+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-48491",
      "initial_release_date": "2026-06-23T19:12:10.819000+00:00",
      "revision_history": [
        {
          "date": "2026-06-23T19:12:10.819000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-26T17:14:06+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:48:30+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Dev Spaces",
                "product": {
                  "name": "Red Hat OpenShift Dev Spaces",
                  "product_id": "red_hat_openshift_dev_spaces",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_devspaces:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Dev Spaces"
          },
          {
            "category": "product_version",
            "name": "devspaces/traefik-rhel9",
            "product": {
              "name": "devspaces/traefik-rhel9",
              "product_id": "devspaces/traefik-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/traefik-rhel9?repository_url=registry.redhat.io/devspaces/traefik-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "devspaces/traefik-rhel9 as a component of Red Hat OpenShift Dev Spaces",
          "product_id": "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
        },
        "product_reference": "devspaces/traefik-rhel9",
        "relates_to_product_reference": "red_hat_openshift_dev_spaces"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-48491",
      "cwe": {
        "id": "CWE-807",
        "name": "Reliance on Untrusted Inputs in a Security Decision"
      },
      "discovery_date": "2026-06-23T20:01:26.461503+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2491923"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This vulnerability allows an unauthenticated client to bypass mutual Transport Layer Security (TLS) enforcement, a security measure that verifies both client and server identities. The bypass occurs due to an issue in Traefik's domain-fronting protection (SNICheck), which incorrectly processes TLS options for HTTP Host headers. As a result, an attacker can gain unauthorized access to protected backend services without presenting a required client certificate.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "Traefik: Traefik: Unauthorized access due to mutual TLS bypass",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important flaw in Traefik that allows an unauthenticated client to bypass mutual TLS authentication. The vulnerability arises from an issue in Traefik's domain-fronting protection when specific wildcard host rules with strict TLS options are used alongside permissive SNI configurations on the same entrypoint. This bypass enables unauthorized access to protected backend services, undermining critical access controls.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-48491"
        },
        {
          "category": "external",
          "summary": "RHBZ#2491923",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491923"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-48491",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48491"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-48491",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48491"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/releases/tag/v3.7.3",
          "url": "https://github.com/traefik/traefik/releases/tag/v3.7.3"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/security/advisories/GHSA-5r4w-85f3-pw66",
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-5r4w-85f3-pw66"
        }
      ],
      "release_date": "2026-06-23T19:12:10.819000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "To mitigate this issue, avoid configuring Traefik with wildcard host rules (e.g., Host(*.example.com)) alongside strict TLS options such as RequireAndVerifyClientCert on entrypoints that also serve permissive SNI configurations. Alternatively, restrict network access to Traefik's entrypoints to trusted networks only, thereby limiting potential exposure.",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "title": "Traefik: Traefik: Unauthorized access due to mutual TLS bypass"
    }
  ]
}