{"id":"CVE-2026-44332","title":"GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer","summary":"GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer","severity":"medium","cvss":5.3,"cwe":["CWE-203"],"vendor":"gofiber","product":"github.com/gofiber/fiber/v3","ecosystem":"go","affected":["github.com/gofiber/fiber/v3 <= 3.2.0"],"patched":["github.com/gofiber/fiber/v3 3.3.0"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-g5vh-55hw-rxm8","references":[{"url":"https://github.com/gofiber/fiber/security/advisories/GHSA-g5vh-55hw-rxm8"},{"url":"https://github.com/advisories/GHSA-g5vh-55hw-rxm8"}],"tags":["ghsa","go"],"ingestedAt":"2026-07-02T14:37:13.957Z","epss":0.00517,"epssPercentile":0.42796,"slug":"CVE-2026-44332","body":"## Overview\n\n## Summary\n\nThe default `Authorizer` function in GoFiber's BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.\n\n## Vulnerable Code\n\n**File:** `middleware/basicauth/config.go`, lines 126-138\n\n```go\nif cfg.Authorizer == nil {\n    verifiers := make(map[string]func(string) bool, len(cfg.Users))\n    for u, hpw := range cfg.Users {\n        v, err := parseHashedPassword(hpw)\n        if err != nil {\n            panic(err)\n        }\n        verifiers[u] = v\n    }\n    cfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {\n        verify, ok := verifiers[user]\n        return ok && verify(pass)   // line 137: short-circuit skips verify() if user unknown\n    }\n}\n```\n\n## Data Flow\n\n1. Attacker sends `Authorization: Basic <base64(candidate:wrongpass)>`\n2. BasicAuth middleware decodes credentials and calls `cfg.Authorizer(user, pass, c)`\n3. Map lookup `verifiers[user]` returns `ok=false` for non-existent users\n4. Go `&&` short-circuit: `false && verify(pass)` returns immediately without calling `verify()`\n5. For valid users, `verify(pass)` executes `bcrypt.CompareHashAndPassword()` (line 167: ~100ms at default cost 10)\n6. Timing difference: ~100ns (invalid user) vs ~100ms (valid user) = 1,000,000:1 ratio\n\n**Timing comparison by hash type:**\n\n| Hash Type | Valid User | Invalid User | Ratio |\n|-----------|-----------|--------------|-------|\n| bcrypt ($2) | ~100 ms | ~100 ns | 1,000,000:1 |\n| SHA-512 | ~1-5 us | ~100 ns | 10-50:1 |\n| SHA-256 | ~1-5 us | ~100 ns | 10-50:1 |\n\n## Impact\n\n- **Username enumeration:** Attacker reliably determines which usernames exist by measuring response latency\n- **Targeted brute force:** After enumerating valid usernames, password brute force is focused only on real accounts\n- **Account discovery:** In applications where usernames are sensitive (internal tools, admin panels), leaking their existence is itself a security issue\n\n## Notes\n\n- Password hash comparisons themselves are timing-safe: `subtle.ConstantTimeCompare` is used correctly for SHA-256 (line 185), SHA-512 (line 176), and bcrypt uses its own constant-time comparison\n- The fix is to always execute a dummy hash comparison for unknown users: `bcrypt.CompareHashAndPassword(dummyHash, []byte(pass))` and discard the result\n- This pattern matches CVE-2023-36456 (Authentik timing oracle) and similar findings in other auth libraries\n\n## Affected packages\n\n- `github.com/gofiber/fiber/v3 <= 3.2.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/gofiber/fiber/v3 3.3.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}