Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-88010
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to enumerate configured usernames.
The vulnerability exists due to an observable timing discrepancy in the BasicAuth middleware's checkPassword function when coalescing concurrent credential checks using a key that depends on the stored secret. A remote attacker can send overlapping requests with the same password and different usernames and compare their response times to enumerate configured usernames.
The overlapping requests must reach the same Traefik process. Credential disclosure and authentication bypass are not possible.