CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

159 vulnerabilities with CWE-208
CVE-2026-13183 HIGH
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-15432 HIGH
Observable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerification
CVE-2026-54685 MEDIUM
FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVSS 5.3
CVE-2026-6656 HIGH
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
CVSS 7.5
CVE-2026-9537 MEDIUM
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison
CVSS 5.3
CVE-2026-56764 LOW
Hono - Timing Attack in basicAuth and bearerAuth Middleware
CVSS 3.7
CVE-2026-21840 LOW
HCL BigFix Platform is affected by a user enumeration vulnerability
CVSS 3.1
CVE-2026-54736 HIGH
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel)
CVE-2026-59218 MEDIUM
Open WebUI: Account enumeration via observable login timing discrepancy
CVSS 5.3
CVE-2026-15041 LOW
389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification
CVSS 3.7
CVE-2026-41516 LOW
OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle
CVSS 2.5
CVE-2026-41515 LOW
OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery
CVSS 2.5
CVE-2026-41514 LOW
OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery
CVSS 2.5
CVE-2026-27882 MEDIUM
Coolify: Timing Attack in GitLab Webhook Token Validation
CVSS 4.8
CVE-2026-13758 LOW
CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path
CVSS 3.7
CVE-2026-6291 MEDIUM
Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption
CVSS 6.5
CVE-2026-47380 MEDIUM
NocoDB: User Enumeration via Sign-In Timing
CVE-2026-48166 MEDIUM
Filament: Timing-based user enumeration on login page
CVSS 5.3
CVE-2026-54411 MEDIUM
Linux-PAM < 1.7.2 - Observable Timing Discrepancy
CVSS 5.9
CVE-2026-48011 LOW
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
CVSS 3.7
CVE-2026-48859 MEDIUM
SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration
CVSS 5.3
CVE-2026-5419 LOW
gnutls - Observable Timing Discrepancy in PKCS#7 Padding Check
CVSS 3.7
CVE-2026-45410 MEDIUM
Time-based user enumeration in TREK authentication endpoint
CVSS 5.3
CVE-2026-5091 MEDIUM
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks
CVSS 5.1
CVE-2026-44061 MEDIUM
Netatalk 1.5.0-4.4.2 and >=4.5.0 - Observable Timing Discrepancy via DES-ECB Authentication
CVSS 5.9
Details
Vulnerabilities 159