Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48020

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 10
CVSS3: 9.1
EPSS Низкий

Описание

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — without satisfying the authentication middleware attached to the protected router. This vulnerability is fixed in 2.11.48, 3.6.19, and 3.7.3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия до 2.11.48 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.6.19 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.3 (исключая)

EPSS

Процентиль: 55%
0.00866
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-288
CWE-22

Связанные уязвимости

CVSS3: 9.1
redhat
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — without satisfying the authentication middleware attached to the protected router. This vulnerability is fixed in 2.11.48, 3.6.19, and 3.7.3.

CVSS3: 10
debian
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, ...

CVSS3: 10
github
около 2 месяцев назад

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

EPSS

Процентиль: 55%
0.00866
Низкий

10 Critical

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-288
CWE-22