Skip to main content

CWE archive

CWE-385 CVEs

Programmatic archive

41 CVEs tagged with CWE-3850 Critical, 9 High, 30 Medium, 2 Low, 0 Unrated.

CVE-2026-6478

Published May 14, 2026

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not a…

CVSS 6.5 · Medium
evidence mentions
37
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-5598

Published Apr 15, 2026

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java.…

CVSS 8.9 · High
evidence mentions
11
Buzz score
37.9

CVE-2025-69893

Published Apr 14, 2026

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe…

CVSS 4.6 · Medium

CVE-2025-66442

Published Apr 1, 2026

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto thro…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59425

Published Oct 7, 2025

vLLM is an inference and serving engine for large language models (LLMs). Before version 0.11.0rc2, the API key support in vLLM performs validation using a method that was vulnera…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9231

Published Sep 30, 2025

Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact s…

CVSS 6.5 · Medium
evidence mentions
15
Buzz score
47.7

CVE-2025-59432

Published Sep 22, 2025

SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to v…

CVSS 6.6 · Medium

CVE-2025-49087

Published Jul 20, 2025

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7396

Published Jul 18, 2025

In wolfSSL release 5.8.2 blinding support is turned on by default for Curve25519 in applicable builds. The blinding configure option is only for the base C implementation of Curve…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53826

Published Jul 15, 2025

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27587

Published Jun 16, 2025

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign…

CVSS 5.3 · Medium

CVE-2025-29780

Published Mar 14, 2025

Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `f…

CVSS 5.8 · Medium

CVE-2024-13176

Published Jan 20, 2025

Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in…

CVSS 4.1 · Medium

CVE-2025-0306

Published Jan 9, 2025

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signa…

CVSS 7.4 · High
evidence mentions
3
Buzz score
25.4

CVE-2024-11862

Published Nov 27, 2024

Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks

CVSS 5.1 · Medium

CVE-2023-46809

Published Sep 7, 2024

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - http…

CVSS 7.4 · High

CVE-2024-45192

Published Aug 22, 2024

An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36405

Published Jun 10, 2024

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A control-flow timing lean has been identified in the reference…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25964

Published Mar 25, 2024

Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leadin…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2236

Published Mar 6, 2024

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to t…

CVSS 5.9 · Medium

CVE-2024-23342

Published Jan 23, 2024

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-c…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49092

Published Nov 28, 2023

RustCrypto/RSA is a portable RSA implementation in pure Rust. Due to a non-constant-time implementation, information about the private key is leaked through timing information whi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2