PT-2026-26602 · Traefik · Traefik
F1Vet
·
Publicado
2026-03-20
·
Atualizado
2026-03-27
·
CVE-2026-32595
CVSS v4.0
6.3
Média
| Vetor | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions 2.11.40 and below
Traefik versions 3.0.0-beta1 through 3.6.11
Traefik version 3.7.0-ea.1
Description
Traefik’s BasicAuth middleware has a flaw that allows an unauthenticated attacker to enumerate valid usernames through a timing attack. When a valid username is submitted, the middleware performs a bcrypt password comparison, taking approximately 166 milliseconds. If the username is invalid, the response is returned immediately in about 0.6 milliseconds. This approximately 298-times timing difference is observable over the network, enabling an attacker to reliably identify valid usernames.
Recommendations
Update to Traefik version 2.11.41 or later.
Update to Traefik version 3.6.11 or later.
Update to Traefik version 3.7.0-ea.2 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Traefik