CVE Explorer
CVE-2026-54762
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret annotations, but the referenced auth Secret cannot be resolved or parsed, Traefik logs the resolution error, skips installing the authentication middlewar
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-636","description":"CWE-636: Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-693","description":"CWE-693: Protection Mechanism Failure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"traefik","vendor":"traefik","versions":[{"status":"affected","version":">= 3.7.0-ea.1, < 3.7.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":5.9,"baseSeverity":"MEDIUM","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-636","description":"CWE-636: Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-693","description":"CWE-693: Protection Mechanism Failure","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/problemTypes/1/descriptions/0
Source references
2 source assertions{"name":"https://github.com/traefik/traefik/releases/tag/v3.7.5","tags":["x_refsource_MISC"],"url":"https://github.com/traefik/traefik/releases/tag/v3.7.5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/references/1
{"name":"https://github.com/traefik/traefik/security/advisories/GHSA-4mr2-fg2p-w63c","tags":["x_refsource_CONFIRM"],"url":"https://github.com/traefik/traefik/security/advisories/GHSA-4mr2-fg2p-w63c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d89c6a91b871a36b666fb4e62d4ff6823c01c219018d2c3f80ff787bf0bae575 · sha256:29c0408785cd96dc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.