Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85595— Traefik before v2.11.55 Authentication Bypass via digestAuth

Quick assessment

Affected
traefik traefik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: Traefik 在 v2.11.55 之前的版本中存在一个认证绕过漏洞,位于 中间件中。当请求中使用未知的用户名时,系统会返回一个空密码(empty secret),而不是直接拒绝该请求。攻击者可以利用这一特性,使用空密码和任意凭据计算出有效的摘要响应,从而在不需要有效用户名和密码的情况下,绕过所有受 保护的路由的认证。

CVSS 9.3 · Critical

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery

Affected Version Matrix 3

VendorProduct Version RangeStatus
traefik traefik < 2.11.55 affected
2.11.55 unaffected
3.0.0≤ 3.7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85595

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Traefik before v2.11.55 Authentication Bypass via digestAuth
Source: CVE Program / CVE List V5
Vulnerability Description
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
traefik traefik 0 ~ 2.11.55 -
traefik traefik 3.0.0 ~ 3.7.12 -

II. Public POCs for CVE-2026-85595

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85595

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85595 (2)

Same Patch Batch · traefik · 2026-09-04 · 4 CVEs total

CVE-2026-85596 8.2 HIGH Traefik v3.7 Authentication Bypass via TLS Option Conflict
CVE-2026-85597 8.2 HIGH Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict
CVE-2026-85594 7.0 HIGH Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

IV. Related Vulnerabilities

V. Comments for CVE-2026-85595

No comments yet


Leave a comment