Junglewise Threat Intelligence
CVE-2026-41263: GO-2026-5195 - Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware in github.com/traefik/traefik
CVE-2026-41263 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Go.
Executive brief
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware in github.com/traefik/traefik
Affected products
- Go github.com/traefik/traefik/v3
- Go github.com/traefik/traefik/v2
- Go github.com/traefik/traefik