Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71326

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 3.8
EPSS Низкий

Описание

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.6.11 (включая) до 3.6.25 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.10 (исключая)

EPSS

Процентиль: 18%
0.00257
Низкий

3.8 Low

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 3.8
redhat
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
debian
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...

github
около 2 месяцев назад

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

CVSS3: 3.3
fstec
около 2 месяцев назад

Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 18%
0.00257
Низкий

3.8 Low

CVSS3

Дефекты

CWE-287