Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-71326

около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2026-71326

около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2026-71326

около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-6765-c87h-8mrf

около 2 месяцев назад

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

EPSS: Низкий
fstec логотип

BDU:2026-11281

около 2 месяцев назад

Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-71326

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-71326

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 3.8
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-71326

Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...

CVSS3: 3.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-6765-c87h-8mrf

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-11281

Уязвимость функции CheckPassword() файла pkg / middlewares / auth / basic_auth.go промежуточного программного обеспечения Traefik BasicAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу