Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-208

MITRE ↗

CWE-208

2
CRITICAL
18
HIGH
34
MEDIUM
24
LOW
91 CVEs · Page 1/2
9.8
CVE-2026-23519

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-

9.0
CVE-2026-41588

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth

8.7
CVE-2026-16315

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe

8.1
CVE-2026-42602

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in

8.1
CVE-2026-47783

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a

8.1
CVE-2026-47784

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me

7.5
CVE-2025-70949

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a t

7.5
CVE-2026-5086

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff

7.5
CVE-2026-40972

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information

7.5
CVE-2026-47373

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in e

7.5
CVE-2026-6656

Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu

7.5
CVE-2026-13183

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic

7.5
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p

7.5
CVE-2026-75589

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time

7.5
CVE-2026-72700

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation

7.5
CVE-2026-18259

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token

7.4
CVE-2025-68621

Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person

7.4
CVE-2025-48630

In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel infor

7.4
CVE-2026-27856

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u

7.4
CVE-2026-53525

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay au

6.5
CVE-2026-6291

Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key

5.9
CVE-2026-23892

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 a

5.9
CVE-2026-3337

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine au

5.9
CVE-2026-28464

OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke

5.9
CVE-2026-32935

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, an

5.9
CVE-2026-33129

H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i

5.9
CVE-2026-21713

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent

5.9
CVE-2026-44061

Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker

5.9
CVE-2017-20240

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq

5.9
CVE-2026-54411

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor

5.9
CVE-2024-14041

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno

5.9
CVE-2026-6727

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a

5.9
CVE-2026-59276

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())

5.3
CVE-2026-23849

File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview,

5.3
CVE-2025-22234

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvi

5.3
CVE-2025-13473

An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. The `django.contrib.auth.handlers

5.3
CVE-2026-25597

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio

5.3
CVE-2026-32702

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c

5.3
CVE-2026-41418

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat

5.3
CVE-2026-41161

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version

5.3
CVE-2026-45410

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attac

5.3
CVE-2026-48859

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem

5.3
CVE-2026-48166

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5

5.3
CVE-2026-59218

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths

5.3
CVE-2026-9537

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()

5.3
CVE-2026-54685

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` a

5.3
CVE-2026-44255

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an

5.3
CVE-2026-82449

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep

5.1
CVE-2026-5091

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us

4.8
CVE-2026-26717

An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operat

Frequently Asked Questions

What is CWE-208?

CWE-208 (CWE-208) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-208?

There are 92 CVE records associated with CWE-208 in our database. Of these, 2 are critical severity, 18 are high severity, and 34 are medium severity.

How can I protect against CWE-208 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-208 using AI-powered security agents.

Detect CWE-208 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-208 vulnerabilities across your infrastructure.

Get Started