CVE-2026-40912Disclosure(traefik / traefik)

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice the percent-encoded raw path. When a dot (or multiple dots) appears in the prefix portion of the URL, the raw path after stripping becomes a dot-segment (e.g. /./admin/secret). ForwardAuth receives this dot-segment path in X-Forwarded-Uri, which does not match the protected path patterns and therefore allows the request through. The backend then normalizes the dot-segment to the real path per RFC 3986 and serves the protected content An unauthenticated attacker can exploit this against any backend that performs dot-segment normalization. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-01)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
traefik

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-30: 1Mentions · 2026-05-01: 3Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 204-3005-01
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-301
Patch1
2026-05-013
Disclosure2General1
Full discourse4 posts
  • CVE@CVEnew
    Patch

    CVE-2026-40912 Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in… https://www.cve.org/CVERecord?id=CVE-2026-40912

    Post summary

    CVE‑2026‑40912 is an authentication bypass in Traefik; older releases are vulnerable, while newer versions (2.11.43, 3.6.14, 3.7.0‑rc.2+) contain the fix.

    00010121
    57.4K followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-40912: Traefik Auth Bypass Flaw Exposes Protected APIs https://thecybrdef.com/cve-2026-40912-traefik-auth-bypass-flaw-exposes-protected-apis/ #CVE202640912 #Traefik #AuthBypass #CyberSecurity #APIsecurity #VulnerabilityAlert #SecurityFlaw #ZeroTrust #InfoSec #CloudSecurity #DevSecOps #CyberThreat #PatchNow #SecurityUpdate

    Post summary

    The article announces an auth bypass flaw in Traefik, CVE‑2026‑40912, that exposes protected APIs. No PoC, exploit code, active exploitation, or patch information is provided in the text.

    0000034
    4 followersView on X
  • cybersecuritypath@cybrsecpath
    General

    CVE-2026-40912: Traefik Auth Bypass Flaw Exposes Protected APIs https://thecybrdef.com/cve-2026-40912-traefik-auth-bypass-flaw-exposes-protected-apis/ #CVE202640912 #Traefik #AuthBypass #CyberSecurity #APIsecurity #VulnerabilityAlert #SecurityFlaw #ZeroTrust #InfoSec #CloudSecurity #DevSecOps #CyberThreat #PatchNow #SecurityUpdate

    Post summary

    The post announces CVE‑2026‑40912 as an auth‑bypass flaw in Traefik but provides no technical details, PoC, exploit code, or evidence of active exploitation or patch information.

    0000027
    8 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40912 Authentication Bypass in Traefik StripPrefixRegex Middleware Prior to 2.11.43 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40912

    Post summary

    The text announces CVE-2026-40912, an authentication bypass in Traefik’s StripPrefixRegex Middleware before version 2.11.43, without providing an exploit, patch, or additional technical details beyond the basic description.

    0000033
    4.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--

Explore more