PT-2026-63358 · Traefik · Traefik
CVSS v4.0
7.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions prior to 2.11.52
Traefik versions 3.6.0 through 3.6.22
Traefik versions 3.7.0 through 3.7.6
Description
An authentication bypass exists in the ReplacePathRegex middleware due to path traversal. When the middleware is configured with a regex that captures user-controlled path segments without a mandatory path separator, it forwards the replaced path to the backend without validating its normalized form. An unauthenticated remote attacker can send a crafted request that produces an un-normalized path, which a backend that normalizes paths may resolve to a protected route, thereby bypassing authentication middleware.
Recommendations
Update to version 2.11.52.
Update to version 3.6.23.
Update to version 3.7.7.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traefik