SB2026050535 - Multiple vulnerabilities in Traefik



SB2026050535 - Multiple vulnerabilities in Traefik

Published: May 5, 2026 Updated: August 21, 2026

Security Bulletin ID SB2026050535
CSH Severity
High
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 43% Medium 14% Low 43%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-41174)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass namespace isolation and apply middleware from another namespace.

The vulnerability exists due to improper access control in the Kubernetes CRD provider Chain middleware resolution path when processing nested middleware references in Middleware.spec.chain.middlewares[] with cross-namespace references disabled. A local user can create or update a local Chain middleware that references middleware objects in another namespace to bypass namespace isolation and apply middleware from another namespace.

Only deployments with providers.kubernetesCRD.allowCrossNamespace=false are affected.


2) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-41263)

CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to enumerate valid usernames.

The vulnerability exists due to observable timing discrepancy in BasicAuth middleware when handling authentication requests. A remote attacker can send authentication attempts and measure response-time differences to enumerate valid usernames.

The issue occurs because the constant-time fallback secret resolves to an empty string, causing the comparison to short-circuit instead of performing a full bcrypt evaluation.


3) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-39858)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and access protected endpoints.

The vulnerability exists due to authentication bypass by spoofing in ForwardAuth and snippet-based authentication middleware when forwarding client-supplied alias forwarded headers to the authentication backend. A remote attacker can send a specially crafted request with spoofed forwarded-header aliases to bypass authentication and access protected endpoints.

Exploitation requires an authentication backend that normalizes underscore and dash header forms equivalently.


4) Insufficient verification of data authenticity (CVE-ID: CVE-2026-35051)

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access to protected backend routes.

The vulnerability exists due to insufficient verification of data authenticity in the ForwardAuth middleware when processing authentication subrequests behind a trusted upstream proxy with trustForwardHeader=false. A remote attacker can supply a spoofed X-Forwarded-Prefix header to bypass authentication and gain unauthorized access to protected backend routes.

Exploitation is security-relevant when the authentication service relies on X-Forwarded-Prefix for authorization or routing decisions, especially when StripPrefix runs before ForwardAuth.


5) Use of Incorrectly-Resolved Name or Reference (CVE-ID: CVE-2026-40912)

CWE-ID: CWE-706 - Use of Incorrectly-Resolved Name or Reference

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication and access protected content.

The vulnerability exists due to use of incorrectly resolved path references in StripPrefixRegex middleware when processing percent-encoded URL paths together with ForwardAuth, BasicAuth, or DigestAuth. A remote attacker can send a specially crafted request with a percent-encoded dot in the prefix portion of the URL to bypass authentication and access protected content.

Exploitation requires a backend that performs dot-segment normalization.


6) Use of multiple resources with duplicate identifier (CVE-ID: CVE-2026-71327)

CWE-ID: CWE-694 - Use of Multiple Resources with Duplicate Identifier

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to redirect traffic to an attacker-controlled backend and disclose sensitive information.

The vulnerability exists due to use of multiple resources with duplicate identifier in the Kubernetes Gateway API provider route identity construction and configuration merge logic when processing accepted HTTPRoute or GRPCRoute objects attached to the same Gateway with equivalent match rules. A remote user can create or modify a colliding Route to redirect traffic to an attacker-controlled backend and disclose sensitive information.

Exploitation requires permission to create or modify a Route accepted by a shared Gateway and a namespace and Route name combination that collides with the victim Route identity.


7) Improper Authentication (CVE-ID: CVE-2026-71326)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to spoof an authenticated identity.

The vulnerability exists due to improper authentication in the BasicAuth middleware when deduplicating concurrent password verifications. A remote privileged user can send concurrent authentication requests with a colliding singleflight key to spoof an authenticated identity.

Exploitation requires knowledge of one valid credential and read access to the corresponding stored password hash. When the BasicAuth headerField option is enabled, the attacker-selected username is forwarded to the backend as a trusted identity.


Remediation

Install update from vendor's website.