Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71326

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 3.8

Описание

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

A flaw was found in Traefik. The BasicAuth middleware in Traefik reuses a key for concurrent password checks, which is generated by concatenating the password and secret without a delimiter. An attacker with a valid credential and the corresponding stored hash can exploit this vulnerability to authenticate as an unconfigured username. This identity spoofing is possible when the 'headerField' is configured to trust forwarded identity information.

Отчет

Red Hat OpenShift Dev Spaces bundles Traefik as a reverse proxy component. The shipped Traefik versions (3.27.1, 3.28.2, 3.29) are newer than the versions affected by this flaw (3.6.11-3.6.25 and 3.7.0-3.7.10), which are already fixed in the shipped releases. No Red Hat product is affected.

Меры по смягчению последствий

No mitigation is necessary; Red Hat products ship Traefik versions outside the vulnerable range.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-836
https://bugzilla.redhat.com/show_bug.cgi?id=2512295github.com/traefik/traefik: Traefik: Authenticated identity spoofing via BasicAuth key collision

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
nvd
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
debian
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...

github
около 2 месяцев назад

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

CVSS3: 3.3
fstec
около 2 месяцев назад

Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

3.8 Low

CVSS3