Critical severityNVD Advisory· Published Sep 4, 2026· Updated Sep 4, 2026
CVE-2026-85595
CVE-2026-85595
Description
Traefik versions before v2.11.55 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.