CVE Database
/

CVE-2026-32595

Back to search

CVE-2026-32595

Published: Mar 20, 2026

Modified: Mar 20, 2026

PUBLISHED

Description

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt password comparison taking ~166ms. When the username does not exist, the response returns immediately in ~0.6ms. This ~298x timing difference is observable over the network and allows an unauthenticated attacker to reliably distinguish valid from invalid usernames. This issue is patched in versions 2.11.41, 3.6.11 and 3.7.0-ea.2.

VendorProductVersions

traefik

traefik

affected
< 2.11.41
affected
>= 3.0.0-beta1, < 3.6.11
affected
>= 3.7.0-ea.1, < 3.7.0-ea.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now