vulnerability
FreeBSD: VID-dc7e30db-de67-11f0-b893-5404a68ad561 (CVE-2025-66491): traefik -- Inverted TLS Verification Logic in Kubernetes NGINX Provider
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:C/I:N/A:N) | Dec 21, 2025 | Jan 27, 2026 | Jan 27, 2026 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Dec 21, 2025
Added
Jan 27, 2026
Modified
Jan 27, 2026
Description
The traefik project reports: There is a potential vulnerability in Traefik NGINX provider managing the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. The provider inverts the semantics of the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backend TLS certificate verification) actually disables verification, allowing man-in-the-middle attacks against HTTPS backends when operators believe they are protected.
Solution
freebsd-upgrade-package-traefik
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.