← All CVEs NewScan detects
critical

CVE-2026-85595

Traefik digestAuth authentication bypass - an unknown username is answered with an empty secret instead of a rejection, so any username with no password authenticates (CVSS 9.3)

Severity
critical
Affected product
Traefik
Affected versions
Traefik ≥ 2.0.0, < 2.11.55
Affected versions
Traefik ≥ 3.0.0, < 3.7.11
Fixed in
Traefik 2.11.55
Fixed in
Traefik 3.7.11
Added to NewScan
2026-09-04
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-04. GHSA-5w68-77r2-r64c, affected verbatim `<= v2.11.54` and `>= v3.0.0, <= v3.7.10`, patched `v2.11.55` and `v3.7.11` - so TWO arms, not the three CVE-2026-71324 needed: this fix did NOT land on a 3.6.x branch, so the 3.x arm is one unbroken ge 3.0.0 / lt 3.7.11 range with no patched gap inside it. Read the fixed-version list per advisory rather than copying the neighbouring row's branch shape. 2.x arm; ge 2.0.0 does not claim 1.x, same reasoning as the CVE-2026-71324 rows.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-85595 (see the 2.x row). MEASURED 2026-09-04 against traefik:v3.7.10 --api.insecure=true on loopback: GET /api/version -> 200 {"Version":"3.7.10","Codename":"langres","startDate":"..."}, inside this row. Negative case measured on traefik:v3.7.11 the same day: /api/version reports 3.7.11, outside every row here and outside CVE-2026-71324's arms - the patched build stays silent.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →