Junglewise Threat Intelligence

CVE-2026-40912: Traefik authentication bypass in StripPrefixRegex middleware

CVE-2026-40912 · Severity: high · CVSS 8.2 · Published 2026-04-30

Technologies: Traefik, Traefik Labs Traefik Proxy, github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Traefik, Traefik Labs, Go.

Executive brief

Traefik, a popular tool for routing and managing web traffic, contains a security flaw in how it handles specific URL prefixes. An attacker can bypass authentication requirements (like passwords or external login checks) by using specially crafted web addresses containing percent-encoded characters. This could allow unauthorized access to sensitive internal data or administrative interfaces that were supposed to be protected.

Technical details

An authentication bypass exists in Traefik's StripPrefixRegex middleware due to a Path/RawPath desynchronization. The middleware calculates the length of a prefix based on the decoded URL path but applies that length to slice the percent-encoded RawPath. When percent-encoded characters (like %2e for a dot) are present in the prefix, the resulting RawPath sent to authentication middlewares (ForwardAuth, BasicAuth, DigestAuth) is malformed (e.g., containing dot-segments like /./). These malformed paths may fail to match protected route patterns in the auth middleware, leading to an 'allow' decision. If the backend server subsequently normalizes the path per RFC 3986, it serves the protected content to the unauthenticated requester. Patches are available in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

Affected products

  • traefik traefik/v2 < 2.11.43
  • traefik traefik/v3 >= 3.0.0-beta1, < 3.6.14; >= 3.7.0-ea.1, < 3.7.0-rc.2
  • traefik traefik <= 1.7.34

Timeline

  • 2026-04-24: advisory
  • 2026-04-24: disclosed
  • 2026-04-24: patched

References

Related threats