THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6765-c87h-8mrf (low) — Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

[GHSA] GHSA-6765-c87h-8mrf (low) — Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

highgithub_advisoriesPublished 2026-08-06

GHSA-6765-c87h-8mrf Severity: low CVE: CVE-2026-71326

Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

## Summary

There is a low severity vulnerability in Traefik's BasicAuth middleware. Concurrent password verifications are deduplicated through a singleflight group whose key was the delimiter-free concatenation of the submitted password and the stored secret

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6765-c87h-8mrf