Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98q5-3v5r-qvfh

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 3.7

Описание

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

EPSS

Процентиль: 14%
0.00229
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 3.7
redhat
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

CVSS3: 3.7
nvd
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

EPSS

Процентиль: 14%
0.00229
Низкий

6.3 Medium

CVSS4

3.7 Low

CVSS3

Дефекты

CWE-208