Back

CRITICAL

Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth

Published Sep 4, 2026

Description

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

Affected products

Remediation

Red Hat statement

A flaw was found in Traefik's digestAuth middleware (versions before v2.11.55 and v3.0.0 through v3.7.10) where requests with unknown usernames are processed using an empty secret instead of being immediately rejected. Within Red Hat environments utilizing affected Traefik components, an unauthenticated remote attacker can exploit this default state by computing a valid HTTP digest response using an empty secret and arbitrary credentials, successfully bypassing authentication on any digestAuth-protected endpoint.

Red Hat mitigation

Disable the digestAuth middleware and transition to alternative authentication mechanisms such as basicAuth, ForwardAuth, or mTLS. Alternatively, restrict network access to digestAuth-protected routes at an upstream gateway or network firewall until patched.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 5, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 4, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity Critical
Public date Sep 4, 2026