Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-208 (通过时间差异性导致的信息暴露) — Vulnerability Class 173

173 vulnerabilities classified as CWE-208 (通过时间差异性导致的信息暴露). AI Chinese analysis included.

CWE-208 represents an information leakage weakness where an application’s response time varies based on internal state, inadvertently revealing sensitive data to external observers. Attackers typically exploit this by measuring the duration of operations, such as login attempts or database queries, to infer the existence of valid usernames or correct password characters. By analyzing these subtle timing differences, adversaries can bypass authentication mechanisms or extract confidential information without direct access. To mitigate this risk, developers must ensure that all security-critical operations take a constant amount of time, regardless of the outcome. This involves implementing uniform error handling, using constant-time comparison algorithms for secrets, and avoiding early returns that expose processing stages. By standardizing execution duration, applications prevent attackers from leveraging timing discrepancies to gain unauthorized insights into system states or credentials.

MITRE CWE Description
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not. In security-relevant contexts, even small variations in timing can be exploited by attackers to indirectly infer certain details about the product's internal operations. For example, in some cryptographic algorithms, attackers can use timing differences to infer certain properties about a private key, making the key easier to guess. Timing discrepancies effectively form a timing side channel.
Common Consequences (1)
Confidentiality, Access Control Read Application Data, Bypass Protection Mechanism
Examples (2)
Consider an example hardware module that checks a user-provided password to grant access to a user. The user-provided password is compared against a golden value in a byte-by-byte manner.
always_comb @ (posedge clk) begin assign check_pass[3:0] = 4'b0; for (i = 0; i < 4; i++) begin if (entered_pass[(i*8 - 1) : i] eq golden_pass([i*8 - 1) : i]) assign check_pass[i] = 1; continue; else assign check_pass[i] = 0; break; end assign grant_access = (check_pass == 4'b1111) ? 1'b1: 1'b0; end
Bad · Verilog
always_comb @ (posedge clk) begin assign check_pass[3:0] = 4'b0; for (i = 0; i < 4; i++) begin if (entered_pass[(i*8 - 1) : i] eq golden_pass([i*8 -1) : i]) assign check_pass[i] = 1; continue; else assign check_pass[i] = 0; continue; end assign grant_access = (check_pass == 4'b1111) ? 1'b1: 1'b0; end
Good · Verilog
In this example, the attacker observes how long an authentication takes when the user types in the correct password.
def validate_password(actual_pw, typed_pw): if len(actual_pw) <> len(typed_pw): return 0 for i in len(actual_pw): if actual_pw[i] <> typed_pw[i]: return 0 return 1
Bad · Python
CVE ID Title CVSS Severity Published
CVE-2026-107269 Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy — gophish 3.7 Low 2026-10-07
CVE-2026-18040 HQC leaks private key information through secret-indexed GF(2^8) tables and a secret-dependent fixed-weight sampler — BC-JAVA 5.9 Medium 2026-10-03
CVE-2026-18036 NTRU leaks private key information by reducing secret values with a non-constant-time integer division — BC-JAVA 8.2 High 2026-10-02
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation — OpenSSL - - 2026-09-29
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V — OpenSSL - - 2026-09-29
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves — OpenSSL - - 2026-09-29
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack — openbao 9.2 Critical 2026-09-23
CVE-2026-85725 LightRAG: Plaintext Passwords Compared Without Constant-Time Function — LightRAG 5.9 Medium 2026-09-22
CVE-2026-88010 Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle — traefik 6.3 Medium 2026-09-22
CVE-2026-95270 dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy — changedetection.io 3.7 Low 2026-09-22
CVE-2026-58272 Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) — server 5.3 Medium 2026-09-21
CVE-2026-77582 Tinyauth: User enumeration attack by timing oracle — tinyauth 6.9 Medium 2026-09-21
CVE-2026-70658 pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature verifier — pay 7.4 High 2026-09-14
CVE-2023-24035 Nagios XI 侧信道信息泄露漏洞 — Nagios XI 3.5 Low 2026-09-14
CVE-2026-87737 OCaml mirage-crypto-ec 侧信道信息泄露漏洞 — mirage-crypto-ec 5.9 Medium 2026-09-09
CVE-2026-16037 Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API WHMCS Module — PayTR Virtual Pos iFrame API WHMCS Module 7.5 High 2026-09-08
CVE-2026-81159 Commerce CyberSource - Moderately critical - Insufficient input validation - SA-CONTRIB-2026-106 — Commerce CyberSource - - 2026-09-02
CVE-2026-84308 phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery — phpseclib 6.3 Medium 2026-09-01
CVE-2026-82449 Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing — cockpit 5.3 Medium 2026-08-29
CVE-2026-55785 free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA — free5gc 3.7 Low 2026-08-28
CVE-2026-78500 Dimension Blind SSRF via Database Test Connection Feature — Dimension 5.1 Medium 2026-08-27
CVE-2026-80199 Kimai before 2.54.0 Username Enumeration via Timing Oracle — kimai 3.7 Low 2026-08-25
CVE-2026-18259 Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090 — Token Content Access - - 2026-08-25
CVE-2026-72701 Grav CMS before 2.0.16 Timing Attack via verifyNonce — grav 3.7 Low 2026-08-25
CVE-2026-72700 Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison — grav 7.5 High 2026-08-25
CVE-2026-53525 WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication — weechat 7.4 High 2026-08-21
CVE-2026-44255 Wazuh: Username Enumeration via Timing Side-Channel — wazuh 5.3 Medium 2026-08-19
CVE-2026-75589 Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify - - 2026-08-19
CVE-2026-16458 Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto — ocrypto 5.9 Medium 2026-08-13
CVE-2026-16459 Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto — Oberon PSA Crypto 5.9 Medium 2026-08-13

Vulnerabilities classified as CWE-208 (通过时间差异性导致的信息暴露) represent 173 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.