CVE-2026-71326 - Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

CVE ID :CVE-2026-71326
Published : Aug. 6, 2026, 10:18 p.m. | 13 minutes ago
Description :Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/Aw65W8f

Post a Comment

Previous Post Next Post