THREAT OPS › Threat News › [GHSA] GHSA-6765-c87h-8mrf (low) — Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
[GHSA] GHSA-6765-c87h-8mrf (low) — Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
GHSA-6765-c87h-8mrf Severity: low CVE: CVE-2026-71326
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
## Summary
There is a low severity vulnerability in Traefik's BasicAuth middleware. Concurrent password verifications are deduplicated through a singleflight group whose key was the delimiter-free concatenation of the submitted password and the stored secret
MITRE ATT&CK techniques
Indicators of compromise
- dbd809b1de85d86d0718c80bedbaabd9aebaa3c6697f9e986ab5f387f4196cb7sha256
- CVE-2026-71326cve
- http://127.0.0.1:19090url
- http://127.0.0.1:8080/api/http/middlewares/auth%40fileurl
Original source: https://github.com/advisories/GHSA-6765-c87h-8mrf