Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-208'

View all threats tagged with 'cwe-208'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-208

Threats Tagged 'cwe-208'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-49506: CWE-208 Observable Timing Discrepancy in Apache Software Foundation Apache Portable Runtime UtilityCVE-2025-49506
0

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

Join the discussion
CVE-2026-16731: CWE-208 Observable timing discrepancy in OMICRON electronics GmbH OMICRON StationScoutCVE-2026-16731
0

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.

Join the discussion
CVE-2026-16315: CWE-208 Observable timing discrepancy in OMICRON electronics GmbH OMICRON StationGuardCVE-2026-16315
0

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters.

Join the discussion
CVE-2026-69247: CWE-208: Observable Timing Discrepancy in pyca cryptographyCVE-2026-69247
0

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.

Join the discussion
CVE-2026-8794: CWE-208 Observable timing discrepancy in PaperCut PaperCut NG/MFCVE-2026-8794
0

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.

Join the discussion
CVE-2024-14041: CWE-208 Observable Timing Discrepancy in Legion of the Bouncy Castle Inc. BC-JAVACVE-2024-14041
0

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attacker able to measure the timing of a large number of decapsulations performed with the same long-term private key can recover that key. These are the KyberSlash1 (Poly.toMsg) and KyberSlash2 (ciphertext compression) divisions. Compression performed during encapsulation operates on values that become the public ciphertext and is not affected.

Join the discussion
CVE-2026-13183: CWE-208 Observable Timing Discrepancy in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13183
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

Join the discussion
CVE-2026-15432: CWE-208 Observable Timing Discrepancy in Google Tink-JavaCVE-2026-15432
0

CVE-2026-15432 is a high-severity vulnerability in Google Tink-Java where the ChunkedMacVerification object uses a non-constant time comparison for verifying MAC tags. This timing discrepancy can act as a side channel, potentially allowing attackers to determine how many bytes of a tag match the correct tag, facilitating a bytewise recovery of the correct tag.

Join the discussion
CVE-2026-54685: CWE-208: Observable Timing Discrepancy in gtsteffaniak filebrowserCVE-2026-54685
0

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.

Join the discussion
CVE-2026-6656: CWE-208 Observable Timing Discrepancy in DRSTEVE Crypt::PasswordCVE-2026-6656
0

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Tag: cwe-208
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses