CVE-2026-85595
EUVD-2026-7101804.09.2026, 12:17
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| traefik | traefik | 𝑥 < 2.11.55 | CNA |
| traefik | traefik | 3.0.0 ≤ 𝑥 ≤ 3.7.12 | CNA |
Common Weakness Enumeration