CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-65600

CVE-2026-65600: Authentication Bypass via Path Traversal in Traefik ReplacePathRegex Middleware

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 6, 2026·6 min read·178 visits

Executive Summary (TL;DR)

A path traversal vulnerability in Traefik's ReplacePathRegex middleware allows unauthenticated remote attackers to bypass gateway authentication controls by exploiting parser differentials and un-normalized path forwarding.

CVE-2026-65600 is a path traversal vulnerability in the ReplacePathRegex middleware component of Traefik. An unauthenticated remote attacker can exploit the vulnerability to inject directory traversal sequences. When Traefik forwards the resulting un-normalized path, downstream backend web servers normalize the request to execute administrative or protected paths, bypassing gateway-enforced security policies.

Vulnerability Overview

Traefik is a modern reverse proxy and ingress controller designed to route incoming network requests to appropriate backend services. Within its routing architecture, Traefik employs various middleware components to inspect, modify, or restrict HTTP requests. The ReplacePathRegex middleware is specifically used to modify request paths using regular expressions prior to proxying.

The vulnerability is classified as improper limitation of a pathname to a restricted directory, or path traversal (CWE-22). The attack surface resides in endpoints configured with this middleware where the regular expression allows loose, non-delimited path capture. Remote, unauthenticated attackers can manipulate the requested path using directory traversal sequences to bypass proxy-level authorization.

By leveraging this flaw, attackers target routes configured with ReplacePathRegex to proxy modified paths to backend applications. If downstream backends perform automatic normalization, they resolve the traversal operators, granting unauthorized access to administrative or restricted handlers. Gateway-enforced authentication policies, such as OAuth2, Basic Auth, or Custom forward authentication, are rendered completely ineffective.

Root Cause Analysis

The root cause of CVE-2026-65600 lies in a parser differential vulnerability combined with a lack of validation after path replacement operations. The ReplacePathRegex middleware executes string substitution based on user-defined regular expression capture groups. However, prior to the fix, the middleware failed to validate or clean the rewritten path before transferring it to the proxy engine.

Consider an environment with a vulnerable regular expression configuration designed to match /api(.*). If an attacker requests /api../admin, the capture group (.*) evaluates to ../admin. The middleware substitutes this capture group into the replacement string, producing a modified path that contains active relative traversal sequences.

Traefik routes the request based on the initial matching logic, which deems /api../admin safe. The internal engine fails to clean the updated URI and forwards the raw traversal sequence to the backend. The downstream web framework (such as Node.js or Spring Boot) then normalizes the path to /admin, exposing the protected interface.

Code Analysis and Patch Verification

Analysis of the patch reveals the exact mechanism used to remediate the vulnerability. The security fix was committed to the Traefik repository within pkg/middlewares/replacepathregex/replace_path_regex.go in commit 3f10dd442479530560f010167cac2947676d9b29 by developer Kevin Pollet.

The modified codebase implements post-replacement normalization and comparison checks:

// pkg/middlewares/replacepathregex/replace_path_regex.go
 
func (rp *replacePathRegex) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
    // ... (replacement execution logic is performed here)
 
    req.RequestURI = req.URL.RequestURI()
 
    // The fix introduces sanitization and comparison verification
    path := req.URL.Path
    if path != "" {
        // JoinPath normalizes the path by resolving dot segments (path.Clean)
        req.URL = req.URL.JoinPath()
    }
 
    // If the cleaned path differs from the replaced path, block execution
    if path != req.URL.Path {
        logger.Debugf("Rejecting request, sanitized path: %q is not equivalent to stripped path: %q", path, req.URL.Path)
        http.Error(rw, http.StatusText(http.StatusBadRequest), http.StatusBadRequest)
        return
    }
}

This implementation utilizes Go's standard library JoinPath() to clean the output path. If the resulting cleaned path differs from the initial un-normalized replacement output, it indicates path traversal manipulation. Traefik logs the event, terminates the connection immediately, and responds with an HTTP 400 Bad Request error.

While the patch successfully stops standard path traversal vectors on UNIX platforms, security teams must monitor for parser discrepancies. Go's native path resolution does not treat backslashes as path separators on UNIX platforms, whereas specific Windows-based backend applications might execute backslash normalization, which represents a potential minor variant risk.

Exploitation and Attack Scenarios

Exploitation requires no user interaction or existing privileges on the system. The attacker only needs network access to the exposed Traefik proxy and knowledge of a route employing the vulnerable middleware. Because path modification occurs invisibly, the downstream server receives and services the unauthorized traffic directly.

In a simulated attack, an operator identifies an API endpoint routed through Traefik with the rule regex: "^/public(.*)". The corresponding target backend hosts both public endpoints and an administrator console located at /secure-admin. Under normal operating parameters, Traefik blocks direct access to /secure-admin using an authentication middleware.

The attacker bypasses this control by transmitting a crafted GET request targeting /public/../../secure-admin. Traefik matches the request to the public rule, passes it through the replacement middleware, and rewrites the path. Since the original middleware failed to normalize the output, Traefik forwards the raw traversal sequence directly to the backend system.

The backend server receives /public/../../secure-admin and immediately normalizes the request to /secure-admin using its native routing rules. It processes the query and returns the sensitive data back to the proxy, bypassing the Traefik-layer authorization check entirely.

Impact Assessment

The security impact of CVE-2026-65600 is classified as high because it nullifies upstream perimeter security controls. Gateways are commonly utilized as centralized security boundaries to enforce authentication, rate limiting, and IP whitelisting. A bypass at this layer exposes entire backend architectures to unauthenticated remote actions.

According to the CVSS v4.0 assessment, this vulnerability receives a base score of 7.8, reflecting high subsequent confidentiality and integrity impacts. An attacker can access administrative APIs, extract confidential information from internal applications, or execute states-changing commands. The vulnerability does not require privileges, specialized system access, or user interaction.

Currently, the exploit status of this vulnerability remains at the proof-of-concept phase. There are no documented instances of weaponized exploitation in the wild, nor is the CVE listed in the CISA KEV catalog. Nevertheless, the ease of exploitation makes immediate remediation critical for organizations relying on Traefik gateways to secure backend services.

Remediation and Mitigation Guidance

The recommended resolution is to upgrade all Traefik instances to the appropriate patched release. Administrators using the v2 branch must upgrade to at least v2.11.52. Organizations deploying v3.6 must migrate to v3.6.23 or later, and those on v3.7 must upgrade to at least v3.7.7.

If immediate software upgrades are not possible, administrators should apply defensive configuration adjustments. Inspect all dynamic configurations containing ReplacePathRegex middleware. Alter the matching regular expressions to enforce a strict slash delimiter, changing patterns like ^/api(.*) to ^/api/(.*) to reduce the traversal capture surface.

Organizations can also deploy external Web Application Firewall (WAF) rules to detect and drop directory traversal patterns within incoming request paths. In parallel, monitor system logs for HTTP 400 errors or requests featuring dot-dot-slash patterns. Upgrading remains the only complete and reliable remediation for the underlying flaw.

Official Patches

traefikOfficial patch commit implementing validation logic inside the ReplacePathRegex middleware
traefikTraefik v2.11.52 Release Notes
traefikTraefik v3.6.23 Release Notes
traefikTraefik v3.7.7 Release Notes

Fix Analysis (1)

Technical Appendix

CVSS Score
7.8/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
EPSS Probability
0.67%
Top 51% most exploited

Affected Systems

Traefik ProxyTraefik Ingress Controller

Affected Versions Detail

Product
Affected Versions
Fixed Version
Traefik
traefik
<= v2.11.51v2.11.52
Traefik
traefik
>= v3.6.0, <= v3.6.22v3.6.23
Traefik
traefik
>= v3.7.0, <= v3.7.6v3.7.7
AttributeDetail
CWE IDCWE-22
Attack VectorNetwork
CVSS v4.07.8 (High)
EPSS Score0.00674
ImpactAuthentication Bypass
Exploit StatusProof of Concept
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as '..' that can resolve to a location outside of the directory.

Known Exploits & Detection

VulnCheckAdvisory detailing path traversal and authentication bypass concepts within Traefik middleware

Vulnerability Timeline

Fix commit authored and merged into Traefik codebase
2026-07-06
Public security advisory GHSA-cxjq-mrr5-89rv and CVE-2026-65600 published
2026-07-22
CVE record details updated on NVD
2026-07-23

References & Sources

  • [1]GHSA-cxjq-mrr5-89rv: Authentication Bypass via ReplacePathRegex
  • [2]NVD - CVE-2026-65600 Detail

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•7 minutes ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
0 views•8 min read
•about 1 hour ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
4 views•8 min read
•about 2 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
3 views•6 min read
•about 3 hours ago•CVE-2026-76485
9.8

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Alon Barad
Alon Barad
6 views•6 min read
•about 3 hours ago•CVE-2026-106451
7.3

CVE-2026-106451: Local Privilege Escalation via JNI Extraction TOCTOU in lz4-java

A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-105698
5.4

CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.

Amit Schendel
Amit Schendel
5 views•8 min read