vulnerability

FreeBSD: VID-dc7e30db-de67-11f0-b893-5404a68ad561 (CVE-2025-66491): traefik -- Inverted TLS Verification Logic in Kubernetes NGINX Provider

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Dec 21, 2025
Added
Jan 27, 2026
Modified
Jan 27, 2026

Description

The traefik project reports: There is a potential vulnerability in Traefik NGINX provider managing the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. The provider inverts the semantics of the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backend TLS certificate verification) actually disables verification, allowing man-in-the-middle attacks against HTTPS backends when operators believe they are protected.

Solution

freebsd-upgrade-package-traefik
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.