Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-32595

 

Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-32595

Published: May 5, 2026


Vulnerability identifier: #VU129670
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-32595
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Traefik
Software vendor:
Containous

Description

The vulnerability allows a remote attacker to enumerate valid usernames.

The vulnerability exists due to observable timing discrepancy in the BasicAuth middleware when validating submitted credentials. A remote attacker can send authentication requests and measure response times to enumerate valid usernames.

Only deployments with the BasicAuth middleware enabled are vulnerable.


Remediation

Install security update from vendor's website.

External links