CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

119 vulnerabilities with CWE-208
CVE-2025-70949 HIGH
@perfood/couch-auth 0.26.0 - Info Disclosure
CVSS 7.5
CVE-2025-48630 HIGH
SkiaRenderEngine - Info Disclosure
CVSS 7.4
CVE-2025-68621 HIGH
Trilium Notes <0.101.0 - Auth Bypass
CVSS 7.4
CVE-2025-13473 MEDIUM
Django <6.0.2-4.2.28 - Info Disclosure
CVSS 5.3
CVE-2025-22234 MEDIUM
Timing Attack Mitigation - Info Disclosure
CVSS 5.3
CVE-2025-52457 MEDIUM
Command Centre Server <9.30.251028a - Info Disclosure
CVSS 5.7
CVE-2025-59438 MEDIUM
Mbed TLS <3.6.4 - Info Disclosure
CVSS 5.3
CVE-2025-54764 MEDIUM
Mbed TLS <3.6.5 - Info Disclosure
CVSS 6.2
CVE-2025-54499 LOW
Mattermost <10.5.10, <10.11.2 - Info Disclosure
CVSS 3.1
CVE-2025-9031 MEDIUM
DivvyDrive Web <4.8.2.15 - XSS
CVSS 4.3
CVE-2025-59432 MEDIUM
SCRAM <3.2 - Timing Attack
CVE-2025-59350 MEDIUM
Dragonfly <2.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-59058 MEDIUM
httpsig-rs <0.0.19 - Timing Attack
CVSS 5.9
CVE-2025-7383 MEDIUM
Oberon PSA Crypto <1.5.1 - Info Disclosure
CVE-2025-7071 MEDIUM
Oberon microsystem AG's ocrypto <3.9.2 - Info Disclosure
CVE-2025-43754 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2025-20067 MEDIUM
Intel(R) CSME/SPS - Info Disclosure
CVSS 6.0
CVE-2025-8774 LOW
riscv-boom SonicBOOM <2.2.3 - Info Disclosure
CVSS 2.5
CVE-2025-53940 HIGH
Quiet <6.1.0-alpha.4 - Timing Attack
CVE-2025-48995 MEDIUM
SignXML <4.0.4 - Info Disclosure
CVE-2025-46570 LOW
vLLM <0.9.0 - Info Disclosure
CVSS 2.6
CVE-2025-27936 MEDIUM
Mattermost Plugin MSTeams <2.1.0 & Mattermost Server 10.5.x <=10.5....
CVSS 5.3
CVE-2025-30344 MEDIUM
OpenSlides <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-29780 MEDIUM
Post-Quantum Secure Feldman's Verifiable Secret Sharing <0.8.0b2 - ...
CVE-2025-0693 MEDIUM
AWS Sign-in < unknown - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 119