Количество 22
Количество 22
GHSA-6r7g-3mm3-fhw7
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time compariso ...
BDU:2026-04835
Уязвимость функции memcmp программной платформы Node.js, связанная с недостаточным сравнением, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260818-80-0010
Уязвимость nodejs24
ROS-20260818-73-0014
Уязвимость nodejs
SUSE-SU-2026:1509-1
Security update for nodejs22
SUSE-SU-2026:1478-1
Security update for nodejs22
SUSE-SU-2026:1371-1
Security update for nodejs20
SUSE-SU-2026:1363-1
Security update for nodejs20
openSUSE-SU-2026:20519-1
Security update for nodejs24
SUSE-SU-2026:1299-1
Security update for nodejs24
RLSA-2026:7670
Important: nodejs:24 security update
ELSA-2026-7670
ELSA-2026-7670: nodejs:24 security update (IMPORTANT)
RLSA-2026:7675
Important: nodejs24 security update
RLSA-2026:7350
Important: nodejs:24 security update
ELSA-2026-7675
ELSA-2026-7675: nodejs24 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6r7g-3mm3-fhw7 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 5 месяцев назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time compariso ... | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
BDU:2026-04835 Уязвимость функции memcmp программной платформы Node.js, связанная с недостаточным сравнением, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
ROS-20260818-80-0010 Уязвимость nodejs24 | CVSS3: 5.9 | 0% Низкий | 27 дней назад | |
ROS-20260818-73-0014 Уязвимость nodejs | CVSS3: 5.9 | 0% Низкий | 27 дней назад | |
SUSE-SU-2026:1509-1 Security update for nodejs22 | 5 месяцев назад | |||
SUSE-SU-2026:1478-1 Security update for nodejs22 | 5 месяцев назад | |||
SUSE-SU-2026:1371-1 Security update for nodejs20 | 5 месяцев назад | |||
SUSE-SU-2026:1363-1 Security update for nodejs20 | 5 месяцев назад | |||
openSUSE-SU-2026:20519-1 Security update for nodejs24 | 5 месяцев назад | |||
SUSE-SU-2026:1299-1 Security update for nodejs24 | 5 месяцев назад | |||
RLSA-2026:7670 Important: nodejs:24 security update | 5 месяцев назад | |||
ELSA-2026-7670 ELSA-2026-7670: nodejs:24 security update (IMPORTANT) | 5 месяцев назад | |||
RLSA-2026:7675 Important: nodejs24 security update | 5 месяцев назад | |||
RLSA-2026:7350 Important: nodejs:24 security update | 5 месяцев назад | |||
ELSA-2026-7675 ELSA-2026-7675: nodejs24 security update (IMPORTANT) | 3 месяца назад |
Уязвимостей на страницу