LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-54762

traefik · traefik

Published
CVSS8.6
Severityhigh
WeaknessCWE-636
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret annotations, but the referenced auth Secret cannot be resolved or parsed, Traefik logs the resolution error, skips installing the authentication middleware, and still emits a router to the backend service. A route that operators intended to protect is therefore published to the data plane without its authentication control, allowing unauthenticated acc

References

← Back to the CVE Tracker

Our coverage of CVE-2026-54762

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-54762.