THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cxjq-mrr5-89rv (critical) — Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

[GHSA] GHSA-cxjq-mrr5-89rv (critical) — Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

highgithub_advisoriesPublished 2026-08-06

GHSA-cxjq-mrr5-89rv Severity: critical CVE: CVE-2026-65600

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

## Summary

There is a critical authentication-bypass vulnerability in Traefik's `ReplacePathRegex` middleware. When it is configured with a regular expression that captures user-controlled path segments without a mandatory separator (for example `regex: "^/

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cxjq-mrr5-89rv