CVE-2026-85595
Traefik digestAuth authentication bypass - an unknown username is answered with an empty secret instead of a rejection, so any username with no password authenticates (CVSS 9.3)
- Severity
- critical
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.0.0, < 2.11.55
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.11
- Fixed in
- Traefik 2.11.55
- Fixed in
- Traefik 3.7.11
- Added to NewScan
- 2026-09-04
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-04. GHSA-5w68-77r2-r64c, affected verbatim `<= v2.11.54` and `>= v3.0.0, <= v3.7.10`, patched `v2.11.55` and `v3.7.11` - so TWO arms, not the three CVE-2026-71324 needed: this fix did NOT land on a 3.6.x branch, so the 3.x arm is one unbroken ge 3.0.0 / lt 3.7.11 range with no patched gap inside it. Read the fixed-version list per advisory rather than copying the neighbouring row's branch shape. 2.x arm; ge 2.0.0 does not claim 1.x, same reasoning as the CVE-2026-71324 rows.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-85595 (see the 2.x row). MEASURED 2026-09-04 against traefik:v3.7.10 --api.insecure=true on loopback: GET /api/version -> 200 {"Version":"3.7.10","Codename":"langres","startDate":"..."}, inside this row. Negative case measured on traefik:v3.7.11 the same day: /api/version reports 3.7.11, outside every row here and outside CVE-2026-71324's arms - the patched build stays silent.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →