Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-32595
Published: May 5, 2026
Traefik
Containous
Description
The vulnerability allows a remote attacker to enumerate valid usernames.
The vulnerability exists due to observable timing discrepancy in the BasicAuth middleware when validating submitted credentials. A remote attacker can send authentication requests and measure response times to enumerate valid usernames.
Only deployments with the BasicAuth middleware enabled are vulnerable.