Feed/CVE-2026-65600
CVE-2026-65600CRITICALCVSS 9.1

CVE-2026-65600

Published Jul 22, 2026·Updated Aug 6, 2026

NVD Description

Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When ReplacePathRegex is configured with a regex that captures user-controlled path segments without a mandatory path separator (e.g. regex "^/api(.*)", replacement "/$1"), the middleware forwards the replaced path to the backend without validating that it matches its normalized form. An unauthenticated remote attacker can send a crafted request (e.g. GET /api../admin) that produces an un-normalized path such as /../admin, which a backend that normalizes paths resolves to a protected route, bypassing authentication middleware. Fixed in v2.11.52, v3.6.23, and v3.7.7.

Affected Packages (3)

github.com/traefik/traefik/v3GO
Fixed in = 3.6.22
github.com/traefik/traefik/v2GO
Fixed in = 2.11.51
github.com/traefik/traefikGO
Fixed in = 1.7.34

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free