Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85595

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

An authentication bypass vulnerability was discovered in Traefik's digestAuth middleware. When an incoming request contains a username that does not exist in the configured authentication store, the application fails to reject the request and instead evaluates the credential against an empty string secret. An unauthenticated remote attacker can exploit this flaw by generating a valid HTTP Digest Authentication header calculated using an empty secret and an arbitrary password, successfully bypassing authentication controls and gaining unauthorized access to routes protected by the digestAuth middleware.

Отчет

A flaw was found in Traefik's digestAuth middleware (versions before v2.11.55 and v3.0.0 through v3.7.10) where requests with unknown usernames are processed using an empty secret instead of being immediately rejected. Within Red Hat environments utilizing affected Traefik components, an unauthenticated remote attacker can exploit this default state by computing a valid HTTP digest response using an empty secret and arbitrary credentials, successfully bypassing authentication on any digestAuth-protected endpoint.

Меры по смягчению последствий

Disable the digestAuth middleware and transition to alternative authentication mechanisms such as basicAuth, ForwardAuth, or mTLS. Alternatively, restrict network access to digestAuth-protected routes at an upstream gateway or network firewall until patched.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2529027github.com/traefik/traefik: Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth

EPSS

Процентиль: 38%
0.00445
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
18 дней назад

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

CVSS3: 9.8
debian
18 дней назад

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 c ...

CVSS3: 9.8
github
18 дней назад

Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

EPSS

Процентиль: 38%
0.00445
Низкий

9.1 Critical

CVSS3