CVE-2026-5419Low· 3.7▾ SunlitA flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through ob…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77987Critical· 9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server
CVE-2026-63132CriticalOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-88010Medium· 6.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-15432Medium· 5.9When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison
CVE-2026-95270Low· 3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7