Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56764

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 3.7
redhat
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

CVSS3: 3.7
github
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3

Дефекты

CWE-208