Loading market data...
← Back to CVE feed

CVE-2026-85595

UNKNOWN View on NVD ↗

Description

Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.

Published: Sep 04, 2026 12:17 UTC Modified: Sep 04, 2026 14:17 UTC