CVEs classified under CWE-208, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2023-41313 — CVSS 9.8 (critical): The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to…
CVE-2026-16315 — CVSS 8.7 (high): OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…
CVE-2024-42512 — CVSS 8.6 (high): Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication…
CVE-2026-43606: Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially…
CVE-2025-53940: Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's…
CVE-2026-16731: OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism…
CVE-2026-69247: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0…
CVE-2024-14041: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients…
CVE-2026-15432: When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This…
CVE-2026-54736: Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied…
CVE-2026-47784 — CVSS 8.1 (high): In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by…
CVE-2026-47783 — CVSS 8.1 (high): In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon…
CVE-2026-42602 — CVSS 8.1 (high): azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension…
CVE-2025-49506 — CVSS 7.5 (high): APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords…
CVE-2026-13183 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through…
CVE-2026-6656 — CVSS 7.5 (high): Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator…
CVE-2026-47373 — CVSS 7.5 (high): Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison…
CVE-2026-40972 — CVSS 7.5 (high): An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote…
CVE-2026-5086 — CVSS 7.5 (high): Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store…
CVE-2025-70949 — CVSS 7.5 (high): An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.
CVE-2021-42016 — CVSS 7.5 (high): A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F…
CVE-2026-53525 — CVSS 7.4 (high): WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses…
CVE-2025-48630 — CVSS 7.4 (high): In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure…
CVE-2025-68621 — CVSS 7.4 (high): Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases…
CVE-2026-8794: PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit…
CVE-2026-44368: PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication…
CVE-2025-48995: SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned…
CVE-2025-59432: SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC…
CVE-2026-6291 — CVSS 6.5 (medium): Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL…
CVE-2024-22340 — CVSS 6.5 (medium): IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow a remote attacker to obtain sensitive information during the…
CVE-2024-23953 — CVSS 6.5 (medium): Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an…
CVE-2024-42368 — CVSS 6.5 (medium): OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and…
CVE-2026-47380: NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between known and unknown…
CVE-2021-34337 — CVSS 6.3 (medium): An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the…
CVE-2025-54764 — CVSS 6.2 (medium): Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or…
CVE-2025-20067 — CVSS 6.0 (medium): Observable timing discrepancy in firmware for some Intel(R) CSME and Intel(R) SPS may allow a privileged user to potentially enable…
CVE-2026-16459: Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1…
CVE-2026-16458: Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an…
CVE-2026-6727 — CVSS 5.9 (medium): A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM…
CVE-2026-54411 — CVSS 5.9 (medium): Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path…
CVE-2017-20240 — CVSS 5.9 (medium): Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison…
CVE-2026-44061 — CVSS 5.9 (medium): Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover…
CVE-2026-21713 — CVSS 5.9 (medium): A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking…
CVE-2026-33129 — CVSS 5.9 (medium): H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability in the…
CVE-2026-32935 — CVSS 5.9 (medium): phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through…
CVE-2026-28464 — CVSS 5.9 (medium): OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens…
CVE-2026-3337 — CVSS 5.9 (medium): Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag…
CVE-2026-23892 — CVSS 5.9 (medium): OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a…
CVE-2025-59058 — CVSS 5.9 (medium): httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not…