Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56764

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

A flaw was found in Hono. This vulnerability, a timing attack, exists in the basicAuth and bearerAuth middlewares due to a non-constant-time string comparison. A remote attacker could exploit the early termination of string equality checks to infer valid credentials by precisely measuring response times, potentially leading to unauthorized access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/mcp-server-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-tech-preview/mcp-server-rhel9Not affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Not affected
Red Hat Hardened Imagesgrafana13-1-main-13.1.1-0.2.hum1FixedRHSA-2026:4761828.07.2026
Red Hat Hardened Imagesgrafana12-4-main-12.4.6-0.2.hum1FixedRHSA-2026:4761928.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2500893hono: Hono - Timing Attack in basicAuth and bearerAuth Middleware

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
nvd
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

CVSS3: 3.7
github
20 дней назад

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

EPSS

Процентиль: 14%
0.00229
Низкий

3.7 Low

CVSS3