CVE-2026-48020
Critical · CVSS 10.0Traefik — Authentication bypass via path traversal in StripPrefix middleware (CWE-288, CWE-22)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-288, CWE-22
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — without satisfying the authentication middleware attached to the protected router. This vulnerability is fixed in 2.11.48, 3.6.19, and 3.7.3.
Search profile — drives PoC discovery
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0containerized · recent activitygh_search · Python
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/traefik/traefik/releases/tag/v2.11.48
- https://github.com/traefik/traefik/releases/tag/v3.6.19
- https://github.com/traefik/traefik/releases/tag/v3.7.3
- https://github.com/traefik/traefik/security/advisories/GHSA-xf64-8mw2-4gr2
- https://access.redhat.com/security/cve/CVE-2026-48020
- https://bugzilla.redhat.com/show_bug.cgi?id=2491915
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48020.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z