Threats Tagged 'cwe-204'
View all threats tagged with 'cwe-204'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-204'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-55998: CWE-204 Observable response discrepancy in SUSE RancherCVE-2026-55998 0 The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle. Join the discussion | CVE Database V5 | 08/05/2026, 07:51:21 UTC Added: 08/05/2026, 08:12:00 UTC |
CVE-2026-60007: CWE-204 in Eclipse Foundation Eclipse MiloCVE-2026-60007 0 In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials. Join the discussion | CVE Database V5 | 08/04/2026, 11:55:41 UTC Added: 08/04/2026, 12:33:19 UTC |
CVE-2026-14202: CWE-204 Observable response discrepancy in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ResourcesCVE-2026-14202 0 Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. Join the discussion | CVE Database V5 | 08/04/2026, 09:07:15 UTC Added: 08/04/2026, 09:18:34 UTC |
CVE-2026-42218: CWE-204: Observable Response Discrepancy in neutrinolabs xrdpCVE-2026-42218 0 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized information disclosure via username enumeration. This issue has been fixed in version 0.10.6.1. Join the discussion | CVE Database V5 | 07/20/2026, 16:44:26 UTC Added: 07/20/2026, 17:12:20 UTC |
CVE-2024-23574: CWE-204: Response Discrepancy Information Leakage in HCLSoftware Aftermarket EPCCVE-2024-23574 0 HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system Join the discussion | CVE Database V5 | 07/17/2026, 13:45:33 UTC Added: 07/18/2026, 11:08:58 UTC |
CVE-2026-47083: CWE-204 Observable Response Discrepancy in cyrusimap Cyrus IMAPCVE-2026-47083 0 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content). Join the discussion | CVE Database V5 | 07/16/2026, 00:00:00 UTC Added: 07/16/2026, 18:48:09 UTC |
CVE-2026-15747: CWE-204 Observable Response Discrepancy in SRI MojoliciousCVE-2026-15747 0 Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation. Join the discussion | CVE Database V5 | 07/14/2026, 17:07:32 UTC Added: 07/14/2026, 17:49:00 UTC |
CVE-2026-44753: CWE-204: Observable Response Discrepancy in SAP_SE SAP HANA Extended Application Services classic model (User Self Service)CVE-2026-44753 0 SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application. Join the discussion | CVE Database V5 | 07/14/2026, 00:19:58 UTC Added: 07/14/2026, 01:03:20 UTC |
Showing 1 to 8 of 8 results