VulnSea

CWE-208

CVEs classified under CWE-208, newest first.

38 CVEsRSS

CVE-2026-54411Medium· 5.9
3mo ago

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeate…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.50%via NVD
CVE-2026-48859Medium· 5.3
3mo ago

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with …

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication. When the SSH daemon is configured with …

▾ Sunliterlang · erlang/otpEPSS 0.62%via NVD
CVE-2026-5419Low· 3.7
3mo ago

A flaw was found in gnutls

A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through ob…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream E4S (v.9.4)EPSS 0.58%via NVD
CVE-2026-47783High· 8.1
4mo ago

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.

▾ Twilightmemcached · memcachedEPSS 1.3%via NVD
CVE-2026-21713Medium· 5.9
6mo ago

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high…

▾ Sunlitnodejs · node.jsEPSS 0.39%via NVD
CVE-2025-59425High· 7.5
11mo ago

vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)

A flaw was found in vLLM’s API token authentication logic, where token comparisons were not performed in constant time. This weakness could allow an attacker to exploit timing differences to guess valid tokens and bypass authentication.

▾ TwilightRed Hat · Red Hat OpenShift AI 3.3EPSS 0.57%via CSAF
CVE-2025-9031Medium· 4.3
1y ago

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc

Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.

▾ SunlitEPSS 0.24%via NVD
CVE-2024-39329Medium· 5.3
2y ago

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing attack involving login requests for use…

▾ Sunlitdjangoproject · djangoEPSS 0.89%via NVD
CWE-208 vulnerabilities (CVEs) — page 2 · VulnSea