Skip to main content

Threats Tagged 'cwe-208'

View all threats tagged with 'cwe-208'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-208

Threats Tagged 'cwe-208'

Click on any threat for detailed analysis and mitigation recommendations

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accounts return without performing the bcrypt comparison used for existing accounts. An unauthenticated attacker can measure response times to enumerate valid usernames or email addresses, facilitating credential-stuffing, password-spraying, and phishing attacks. Version 2.4.1 contains a patch.

Join the discussion

Tinyauth versions prior to 5.1.0 have a timing discrepancy vulnerability that allows remote attackers to distinguish between existing and nonexistent usernames during authentication attempts. This is due to faster response times when a username is missing compared to when bcrypt password verification occurs for existing users. The vulnerability enables attackers to enumerate valid usernames, facilitating targeted credential attacks. The issue is fixed in version 5.1.0.

Join the discussion

Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token from the Paddle-Signature header using Ruby String#==. An unauthenticated remote attacker who can repeatedly submit requests to /pay/webhooks/paddle_billing and obtain sufficiently precise timing measurements can infer matching digest prefixes and recover a valid signature. A forged accepted webhook is enqueued through Pay::Webhooks::ProcessJob and can cause a host application to update billing state, provision paid features, record refunds, or trigger customer notifications. This issue is fixed in version 11.6.2.

Join the discussion

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

Join the discussion

Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

Join the discussion

Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.

Join the discussion
0

CVE-2026-78500 is a medium severity vulnerability in WatchGuard Dimension version 2.0. It is a blind server-side request forgery (SSRF) issue in the Database Server Test configuration that allows an authenticated privileged attacker to enumerate network services on adjacent systems.

Join the discussion

CVE-2026-59276 is a timing discrepancy vulnerability in Spring Security where security-sensitive string comparisons use standard equality checks instead of constant-time comparisons. This causes the time taken to reject incorrect values to vary based on the number of matching leading characters. The vulnerability affects multiple versions of Spring Security including 5.7.0 through 7.1.0. The CVSS score is 5.9, indicating medium severity.

Join the discussion

An observable timing discrepancy vulnerability exists in the Drupal Token Content Access module, allowing brute force attacks. This affects versions from 0.0.0 up to but not including 3.1.2. The vulnerability has a high severity with a CVSS score of 7.5, indicating network attack vector with low attack complexity and no privileges or user interaction required. The vulnerability impacts confidentiality but not integrity or availability.

Join the discussion
0

Net::OAuth versions before 0.33 for Perl use a non-constant-time comparison when verifying HMAC-SHA1, HMAC-SHA256, and PLAINTEXT signatures. This timing discrepancy allows an attacker who can submit messages and measure response times to recover valid signatures byte-by-byte. The PLAINTEXT method is particularly vulnerable as it compares against the signature key itself, potentially exposing consumer_secret and token_secret. RSA-SHA1 verification is not affected. The vulnerability has a high severity with a CVSS score of 7.5.

Join the discussion

Showing 1 to 10 of 76 results

Filters:Tag: cwe-208
Page 1 of 8
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses