CVE-2026-85595
Traefik before v2.11.55 Authentication Bypass via digestAuth
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
| CWE | CWE-287 |
| Vendor | traefik |
| Product | traefik |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for traefik traefik
Be the first to know when new unknown vulnerabilities affecting traefik traefik are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
traefik / traefik
0 < 2.11.55
traefik / traefik
3.0.0 โค 3.7.12
References
Credits
๐ matiasinsaurralde