Количество 5
Количество 5
CVE-2026-71326
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.
CVE-2026-71326
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.
CVE-2026-71326
Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...
GHSA-6765-c87h-8mrf
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
BDU:2026-11281
Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-71326 Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10. | CVSS3: 3.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-71326 Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10. | CVSS3: 3.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-71326 Traefik is an open source HTTP reverse proxy and load balancer. From 3 ... | CVSS3: 3.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-6765-c87h-8mrf Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing | 0% Низкий | около 2 месяцев назад | ||
BDU:2026-11281 Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 3.3 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу