Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
Published Sep 4, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.69%
Description
Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
Affected products
-
- Version 0StatusaffectedConstraints<2.11.55
- Version 3.0.0StatusaffectedConstraints<=3.7.12
- Version 2.11.55StatusunaffectedConstraints-
- Version
No data.
Red Hat OpenShift Dev Spaces
devspaces/traefik-rhel9
Affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in Traefik's digestAuth middleware (versions before v2.11.55 and v3.0.0 through v3.7.10) where requests with unknown usernames are processed using an empty secret instead of being immediately rejected. Within Red Hat environments utilizing affected Traefik components, an unauthenticated remote attacker can exploit this default state by computing a valid HTTP digest response using an empty secret and arbitrary credentials, successfully bypassing authentication on any digestAuth-protected endpoint.
Red Hat mitigation
Disable the digestAuth middleware and transition to alternative authentication mechanisms such as basicAuth, ForwardAuth, or mTLS. Alternatively, restrict network access to digestAuth-protected routes at an upstream gateway or network firewall until patched.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-85595 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529027 Issue Tracking
- https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c vendor-advisoryPatchVendor AdvisoryExploitMitigation
- https://nvd.nist.gov/vuln/detail/CVE-2026-85595
- https://www.cve.org/CVERecord?id=CVE-2026-85595
- https://www.vulncheck.com/advisories/traefik-before-2.11.55-authentication-bypass-via-digestauth third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-85595 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529027 | Issue Tracking | |
| https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c | vendor-advisoryPatchVendor AdvisoryExploitMitigation | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-85595 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-85595 | ||
| https://www.vulncheck.com/advisories/traefik-before-2.11.55-authentication-bypass-via-digestauth | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.