CWE-208

Observable Timing Discrepancy

Parent: CWE-203 - Observable Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

159 vulnerabilities with CWE-208
CVE-2025-7071 MEDIUM
Oberon microsystem AG's ocrypto <3.9.2 - Info Disclosure
CVE-2025-43754 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2025-20067 MEDIUM
Intel(R) CSME/SPS - Info Disclosure
CVSS 6.0
CVE-2025-8774 LOW
riscv-boom SonicBOOM <2.2.3 - Info Disclosure
CVSS 2.5
CVE-2025-53940 HIGH
Quiet <6.1.0-alpha.4 - Timing Attack
CVE-2025-48995 MEDIUM
SignXML < 4.0.4 - Observable Timing Discrepancy in HMAC Verification
CVE-2025-46570 LOW
vllm < 0.9.0 - Observable Timing Discrepancy in PageAttention Prefill
CVSS 2.6
CVE-2025-27936 MEDIUM
Mattermost Plugin MSTeams <2.1.0 & Mattermost Server 10.5.x <=10.5....
CVSS 5.3
CVE-2025-30344 MEDIUM
OpenSlides <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-29780 MEDIUM
Post-Quantum Secure Feldman's Verifiable Secret Sharing <0.8.0b2 - ...
CVE-2025-0693 MEDIUM
AWS Sign-in < unknown - Info Disclosure
CVSS 5.3
CVE-2024-14041 HIGH
ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)
CVE-2024-36469 LOW
Zabbix 5.0.0 through 5.0.46 - Information Disclosure via Login Timing
CVSS 3.1
CVE-2024-13939 HIGH
String::Compare::ConstantTime < 0.321 - Observable Timing Discrepancy
CVSS 7.5
CVE-2024-22340 MEDIUM
IBM Common Cryptographic Architecture <7.5.51 - Info Disclosure
CVSS 6.5
CVE-2024-54772 MEDIUM
MikroTik RouterOS <7.17.2 - Info Disclosure
CVSS 5.4
CVE-2024-42512 HIGH
OPC UA .NET Standard Stack <1.5.374.158 - Auth Bypass
CVSS 8.6
CVE-2024-23953 MEDIUM
Apache Hive 2.2.0-4.0.0 - Authenticated Observable Timing Discrepancy in LlapSignerImpl
CVSS 6.5
CVE-2024-56738 MEDIUM
GNU GRUB2 < 2.12 - Observable Timing Discrepancy in grub_crypto_memcmp
CVSS 5.3
CVE-2024-52307 MEDIUM
authentik < 2024.8.5 - Observable Timing Discrepancy in Metrics Endpoint
CVSS 5.6
CVE-2024-31074 MEDIUM
Intel QAT Engine <v1.6.1 - Info Disclosure
CVSS 5.9
CVE-2024-41741 MEDIUM
IBM TXSeries for Multiplatforms 10.1 - Info Disclosure
CVSS 5.3
CVE-2024-7010 MEDIUM
mudler/localai <2.17.1 - Info Disclosure
CVSS 5.9
CVE-2024-47178 MEDIUM
basic-auth-connect <1.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-45052 MEDIUM
Fides < 2.44.0 - Unauthenticated Timing-Based Username Enumeration via Authentication Response
CVSS 5.3
Details
Vulnerabilities 159