blob: cc48a63efc49ada5cd341d8767b7c6fbf816f4dd [file]
id: GO-2026-4792
modules:
- module: github.com/traefik/traefik
unsupported_versions:
- last_affected: 1.7.34
vulnerable_at: 1.7.34
- module: github.com/traefik/traefik/v2
versions:
- fixed: 2.11.41
vulnerable_at: 2.11.40
- module: github.com/traefik/traefik/v3
versions:
- fixed: 3.6.11
- introduced: 3.7.0-ea.1
- fixed: 3.7.0-ea.2
vulnerable_at: 3.7.0-ea.1
summary: |-
Traefik Affected by BasicAuth Middleware Timing Attack Allows Username
Enumeration in github.com/traefik/traefik
cves:
- CVE-2026-32595
ghsas:
- GHSA-g3hg-j4jv-cwfr
references:
- advisory: https://github.com/traefik/traefik/security/advisories/GHSA-g3hg-j4jv-cwfr
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-32595
- web: https://github.com/traefik/traefik/releases/tag/v2.11.41
- web: https://github.com/traefik/traefik/releases/tag/v3.6.11
- web: https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.2
source:
id: GHSA-g3hg-j4jv-cwfr
created: 2026-03-23T12:35:23.459388981-04:00
review_status: UNREVIEWED