{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48020.json"
      }
    ],
    "title": "github.com/traefik/traefik: Traefik: Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths",
    "tracking": {
      "current_release_date": "2026-06-30T03:48:18+00:00",
      "generator": {
        "date": "2026-06-30T03:48:18+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-48020",
      "initial_release_date": "2026-06-23T19:10:31.557000+00:00",
      "revision_history": [
        {
          "date": "2026-06-23T19:10:31.557000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-26T17:14:06+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T03:48:18+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Dev Spaces",
                "product": {
                  "name": "Red Hat OpenShift Dev Spaces",
                  "product_id": "red_hat_openshift_dev_spaces",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_devspaces:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Dev Spaces"
          },
          {
            "category": "product_version",
            "name": "devspaces/traefik-rhel9",
            "product": {
              "name": "devspaces/traefik-rhel9",
              "product_id": "devspaces/traefik-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/traefik-rhel9?repository_url=registry.redhat.io/devspaces/traefik-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "devspaces/traefik-rhel9 as a component of Red Hat OpenShift Dev Spaces",
          "product_id": "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
        },
        "product_reference": "devspaces/traefik-rhel9",
        "relates_to_product_reference": "red_hat_openshift_dev_spaces"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-48020",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "discovery_date": "2026-06-23T20:00:57.714939+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2491915"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This vulnerability exists in the StripPrefix middleware, allowing an unauthenticated attacker to bypass route-level authentication and authorization. By crafting a request path containing '..' or its percent-encoded form, an attacker can access protected backend paths, such as administrative or internal configuration endpoints, without proper authentication. This could lead to unauthorized information disclosure or modification of sensitive settings.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "github.com/traefik/traefik: Traefik: Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is an Important authentication bypass flaw in Traefik's StripPrefix middleware, affecting Red Hat OpenShift Dev Spaces. An unauthenticated remote attacker can exploit this by crafting a specific request path, gaining access to protected backend resources like administrative or internal configuration endpoints. This could lead to unauthorized information disclosure or modification of sensitive settings.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-48020"
        },
        {
          "category": "external",
          "summary": "RHBZ#2491915",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491915"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-48020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-48020"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-48020",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48020"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/releases/tag/v2.11.48",
          "url": "https://github.com/traefik/traefik/releases/tag/v2.11.48"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/releases/tag/v3.6.19",
          "url": "https://github.com/traefik/traefik/releases/tag/v3.6.19"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/releases/tag/v3.7.3",
          "url": "https://github.com/traefik/traefik/releases/tag/v3.7.3"
        },
        {
          "category": "external",
          "summary": "https://github.com/traefik/traefik/security/advisories/GHSA-xf64-8mw2-4gr2",
          "url": "https://github.com/traefik/traefik/security/advisories/GHSA-xf64-8mw2-4gr2"
        }
      ],
      "release_date": "2026-06-23T19:10:31.557000+00:00",
      "remediations": [
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_openshift_dev_spaces:devspaces/traefik-rhel9"
          ]
        }
      ],
      "title": "github.com/traefik/traefik: Traefik: Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths"
    }
  ]
}