以下是该漏洞描述的中文翻译: Traefik 在 v2.11.55 之前的版本中存在一个认证绕过漏洞,位于 中间件中。当请求中使用未知的用户名时,系统会返回一个空密码(empty secret),而不是直接拒绝该请求。攻击者可以利用这一特性,使用空密码和任意凭据计算出有效的摘要响应,从而在不需要有效用户名和密码的情况下,绕过所有受 保护的路由的认证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85596 | 8.2 HIGH | Traefik v3.7 Authentication Bypass via TLS Option Conflict |
| CVE-2026-85597 | 8.2 HIGH | Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict |
| CVE-2026-85594 | 7.0 HIGH | Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware |
No comments yet