CVE-2026-32595General(traefik / traefik)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt password comparison taking ~166ms. When the username does not exist, the response returns immediately in ~0.6ms. This ~298x timing difference is observable over the network and allows an unauthenticated attacker to reliably distinguish valid from invalid usernames. This issue is patched in versions 2.11.41, 3.6.11 and 3.7.0-ea.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
traefik

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 1Mentions · 2026-04-24: 1Technical Details · 2026-03-20: 1Technical Details · 2026-04-24: 103-2003-2204-24
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
2026-04-241
General1
Full discourse3 posts
  • DailyCVE@dailycve
    General

    🟠 Traefik, Timing Side-Channel Username Enumeration, #CVE-2026-32595 (Medium) https://dailycve.com/traefik-timing-side-channel-username-enumeration-cve-2026-32595-medium/

    Post summary

    The link announces a medium‑severity timing side‑channel username enumeration vulnerability in Traefik (CVE‑2026‑32595), but offers no PoC, exploit code, active‑exploitation claim, or patch information.

    0000035
    183 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32595 Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows us… https://www.cve.org/CVERecord?id=CVE-2026-32595

    Post summary

    The message announces a new CVE (CVE‑2026‑32595) for Traefik, listing affected versions but providing no additional details, PoC, or evidence of exploitation.

    00000103
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32595 Traefik BasicAuth Middleware Timing Attack Enables Username Enumeration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32595

    Post summary

    The text describes a timing‑based username enumeration vulnerability in Traefik’s BasicAuth middleware, but offers no details on PoC, exploit code, active exploitation, or remediation.

    0000046
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---
Apptraefiktraefik3.7.0--

Explore more