Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision
This low-severity Red Hat Linux advisory covers CVE-2026-71326.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Traefik is an open source HTTP reverse proxy and load balancer.
From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity.
This issue is fixed in 3.6.25 and 3.7.10. A flaw was found in Traefik.
This identity spoofing is possible when the 'headerField' is configured to trust forwarded identity information. Red Hat OpenShift Dev Spaces bundles Traefik as a reverse proxy component.
No Red Hat product is affected. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Weakness: CWE-836.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- 3.6.25
- 3.7.10
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- No mitigation is necessary; Red Hat products ship Traefik versions outside the vulnerable range.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.