3.8

CVE-2026-71326

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Traefik ≫ Traefik Version >= 3.6.11 < 3.6.25
Traefik ≫ Traefik Version >= 3.7.0 < 3.7.10
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.283
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.8 1.2 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
security-advisories@github.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

https://github.com/traefik/traefik/releases/tag/v3.6.25
Patch
Release Notes
https://github.com/traefik/traefik/releases/tag/v3.7.10
Patch
Release Notes
https://github.com/traefik/traefik/commit/b5ace8eb5d6779980567f5e75efd2d9e08b7e350
Patch
https://github.com/traefik/traefik/pull/13572
Patch
https://github.com/traefik/traefik/security/advisories/GHSA-6765-c87h-8mrf
Patch
Vendor Advisory