5.3
CVE-2026-44332
- EPSS 0.41%
- Veröffentlicht 08.07.2026 19:32:15
- Zuletzt bearbeitet 15.07.2026 20:52:13
- CVE-Watchlists
- Unerledigt
Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.336 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
https://github.com/gofiber/fiber/security/advisories/GHSA-g5vh-55hw-rxm8
https://github.com/gofiber/fiber/pull/4245
https://github.com/gofiber/fiber/commit/c7ac00edd19f9669b1aebbec6e229658baaa059e
https://github.com/gofiber/fiber/releases/tag/v3.3.0