Improper Authentication in Traefik - CVE-2026-71326
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to spoof an authenticated identity.
The vulnerability exists due to improper authentication in the BasicAuth middleware when deduplicating concurrent password verifications. A remote privileged user can send concurrent authentication requests with a colliding singleflight key to spoof an authenticated identity.
Exploitation requires knowledge of one valid credential and read access to the corresponding stored password hash. When the BasicAuth headerField option is enabled, the attacker-selected username is forwarded to the backend as a trusted identity.