HTTP/3 mTLS bypass in Traefik router TLSOptions selection
This vulnerability affects Traefik deployments with HTTP/3 enabled and router-specific TLSOptions used as an mTLS boundary.
An unauthenticated client could complete QUIC/TLS without a client certificate and still reach a backend the operator expected to be mTLS-protected.
Score
7.8/10
High