Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-88010

 

Information Exposure Through Timing Discrepancy in Traefik - CVE-2026-88010

Published: October 7, 2026


Vulnerability identifier: #VU153905
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-88010
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to enumerate configured usernames.

The vulnerability exists due to an observable timing discrepancy in the BasicAuth middleware's checkPassword function when coalescing concurrent credential checks using a key that depends on the stored secret. A remote attacker can send overlapping requests with the same password and different usernames and compare their response times to enumerate configured usernames.

The overlapping requests must reach the same Traefik process. Credential disclosure and authentication bypass are not possible.


Affected software

Traefik

How to mitigate CVE-2026-88010

Install security update from vendor's website.

Traefik - update to 3.7.13

External References

Related Security Bulletins