Junglewise Threat Intelligence

Traefik auth bypass via path traversal in ReplacePathRegex middleware

Severity: high · CVSS 7.8 · Published 2026-07-22

Technologies: Traefik Labs Traefik Proxy, github.com/traefik/traefik/v2 (Go). Vendors: Traefik Labs, Go.

Executive brief

Traefik, a popular open-source edge router and load balancer, is vulnerable to a security flaw that allows attackers to bypass authentication. By sending specially crafted web requests, an unauthorized user can trick the system into granting access to protected internal resources or administrative panels. This could lead to unauthorized data access or full compromise of backend services managed by Traefik.

Technical details

A path traversal vulnerability exists in Traefik's ReplacePathRegex middleware when configured with regular expressions that capture user-controlled path segments without mandatory separators (e.g., '^/api(.*)'). The middleware fails to validate that the resulting replaced path matches its normalized form before forwarding it to the backend. An unauthenticated remote attacker can exploit this by sending a crafted request like 'GET /api../admin', which resolves to an un-normalized path such as '/../admin'. If the backend service normalizes this path, it may grant access to protected routes, effectively bypassing Traefik's authentication middleware. The issue is fixed in versions 2.11.52, 3.6.23, and 3.7.7.

Affected products

  • Traefik Labs Traefik <= v2.11.51, >= v3.6.0 <= v3.6.22, >= v3.7.0 <= v3.7.6

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory
  • 2026-08-06: other: Advisory withdrawn as duplicate of GHSA-cxjq-mrr5-89rv

References

Related threats