CRITICAL 9.3 NVD
CVE-2026-85595
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret ins
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
References
- https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c
- https://www.vulncheck.com/advisories/traefik-before-2.11.55-authentication-bypass-via-dige
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-04 via NVD.
Risk Timeline
CVE Disclosed2026-09-04 · -1 days ago
Remediation Resources
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.