Skip to main content

CWE archive

CWE-208 CVEs

Programmatic archive

159 CVEs tagged with CWE-2083 Critical, 29 High, 94 Medium, 33 Low, 0 Unrated.

CVE-2024-14041

Published Jul 28, 2026

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decod…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-13183

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling r…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15432

Published Jul 21, 2026

When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig in…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54685

Published Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. W…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-6656

Published Jul 20, 2026

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9537

Published Jul 17, 2026

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed H…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56764

Published Jul 15, 2026

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function.…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-21840

Published Jul 14, 2026

HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some lev…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54736

Published Jul 10, 2026

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HM…

CVSS 8.2 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-59218

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran bcry…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-41516

Published Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versi…

CVSS 2.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41515

Published Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versi…

CVSS 2.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41514

Published Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versi…

CVSS 2.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27882

Published Jun 30, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time s…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13758

Published Jun 29, 2026

CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it agains…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
25.4

CVE-2023-20572

Published Jun 26, 2026

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of a…

CVSS 5.6 · Medium

CVE-2023-20540

Published Jun 26, 2026

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary mess…

CVSS 1.8 · Low

CVE-2026-6291

Published Jun 25, 2026

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes dep…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-47380

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown email addresses because the unknown-user…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48166

Published Jun 22, 2026

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54411

Published Jun 14, 2026

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that a…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
32.9

CVE-2017-20240

Published Jun 12, 2026

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess…

CVSS 5.9 · Medium

CVE-2026-48011

Published Jun 10, 2026

Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attac…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-48859

Published Jun 10, 2026

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in passwor…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 159 CVEsPage 1 of 7