PT-2026-63358 · Traefik · Traefik

·

CVE-2026-65600

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

7.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 2.11.52 Traefik versions 3.6.0 through 3.6.22 Traefik versions 3.7.0 through 3.7.6
Description An authentication bypass exists in the ReplacePathRegex middleware due to path traversal. When the middleware is configured with a regex that captures user-controlled path segments without a mandatory path separator, it forwards the replaced path to the backend without validating its normalized form. An unauthenticated remote attacker can send a crafted request that produces an un-normalized path, which a backend that normalizes paths may resolve to a protected route, thereby bypassing authentication middleware.
Recommendations Update to version 2.11.52. Update to version 3.6.23. Update to version 3.7.7.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65600
GHSA-CXJQ-MRR5-89RV

Affected Products

Traefik