Executive brief
Authelia is an open-source tool that provides secure login and single sign-on (SSO) for web applications. A security flaw in how it handles usernames during 'Basic Auth' logins could allow an attacker to bypass brute-force protections. By slightly changing the capitalization of a username (e.g., 'User' vs 'user'), an attacker can reset the login attempt counter, making it easier to guess passwords without being blocked.
Technical details
A vulnerability exists in Authelia's 'authz' verification endpoint when Basic Authentication is used in conjunction with an LDAP backend. While LDAP is case-insensitive for authentication, Authelia's regulation system (which handles rate limiting and bans) treats usernames case-sensitively in its SQL lookups. An attacker can exploit this by submitting the same username with different casing (e.g., 'admin', 'Admin', 'ADMIN'), effectively giving each variation its own 'ban bucket' and bypassing brute-force protections. This issue affects versions 4.38.0 through 4.39.19. It is mitigated if the underlying database uses case-insensitive collation (like some MySQL configurations) or if IP-based regulation is enabled. The fix, introduced in version 4.39.20, implements proper username canonicalization.
Affected products
- Authelia Authelia >= 4.38.0, < 4.39.20
Timeline
- 2026-05-26: patched: Fix committed to repository
- 2026-06-19: disclosed: Public advisory published