CWE-204
AllowedObservable Response Discrepancy
Abstraction: Base · Status: Incomplete
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
357 vulnerabilities reference this CWE, most recent first.
GHSA-HXJ8-JJXP-P43W
Vulnerability from github – Published: 2025-11-12 18:31 – Updated: 2025-11-12 18:31Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.
{
"affected": [],
"aliases": [
"CVE-2025-25236"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-11-12T18:15:35Z",
"severity": "MODERATE"
},
"details": "Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user accounts that could facilitate brute-force, password-spraying or credential-stuffing attacks.",
"id": "GHSA-hxj8-jjxp-p43w",
"modified": "2025-11-12T18:31:25Z",
"published": "2025-11-12T18:31:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25236"
},
{
"type": "WEB",
"url": "https://static.omnissa.com/sites/default/files/OMSA-2025-0005.pdf"
},
{
"type": "WEB",
"url": "https://www.omnissa.com/omnissa-security-response"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-J2HG-VP99-659F
Vulnerability from github – Published: 2026-02-13 00:32 – Updated: 2026-02-13 00:32DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
{
"affected": [],
"aliases": [
"CVE-2019-25338"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-02-12T23:16:07Z",
"severity": "MODERATE"
},
"details": "DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server\u0027s error response messages.",
"id": "GHSA-j2hg-vp99-659f",
"modified": "2026-02-13T00:32:52Z",
"published": "2026-02-13T00:32:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25338"
},
{
"type": "WEB",
"url": "https://download.dokuwiki.org"
},
{
"type": "WEB",
"url": "https://www.dokuwiki.org/dokuwiki"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/47731"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/dokuwiki-b-username-enumeration"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-J7F5-GFQM-PCX3
Vulnerability from github – Published: 2026-06-26 20:54 – Updated: 2026-06-26 20:54Summary
An unprotected user enumeration vulnerability exists in the account email update endpoint, allowing authenticated users to verify whether email addresses are registered on the panel through automated requests without rate limiting or CAPTCHA protection.
Details
The account settings page allows authenticated users to update their email address through a POST request. Unlike the login and password reset forms which implement reCAPTCHA and rate limiting protections, this endpoint lacks these safeguards entirely. An attacker can capture the email update request (for example, using Burp Suite's proxy) and modify the email field to test arbitrary addresses. The panel's response will confirm whether each tested email is already registered in the system. Because there are no rate limits implemented, attackers can send hundreds or thousands of requests to enumerate the user base.
This is concerning because:
- The login and password reset pages correctly implement protections against enumeration
- The account page has no reCAPTCHA option available
- No rate limiting exists in the panel for this endpoint
- Authentication is required, but any valid account (including free tier/trial accounts) can exploit this
PoC
- Log into the Pterodactyl panel with any valid account
- Navigate to Account Settings
- Open Burp Suite (or similar proxy tool) and configure your browser to proxy through it
- Attempt to change your email address and capture the POST request
- Send the captured request to Repeater
- Modify the email field to test different addresses (e.g., admin@example.com, test@example.com)
- Send multiple requests in rapid succession
- Observe the response messages which confirm whether each email exists or not
- Repeat indefinitely without encountering rate limits or CAPTCHA challenges
Impact
This is a user enumeration vulnerability (CWE-204: Observable Response Discrepancy).
Who is impacted:
- All Pterodactyl panel installations are affected
- Any registered user's email address can be discovered
- Particularly impacts administrators and high-value accounts
Potential consequences:
- Attackers can build a complete database of registered users
- Enumerated emails can be used for targeted phishing campaigns
- Combined with other attacks (credential stuffing, social engineering)
- Privacy violation for all users on the platform
- Competitive intelligence gathering (identifying which companies/individuals use specific panels)
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "pterodactyl/panel"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.12.3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-26T20:54:38Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Summary\nAn unprotected user enumeration vulnerability exists in the account email update endpoint, allowing authenticated users to verify whether email addresses are registered on the panel through automated requests without rate limiting or CAPTCHA protection.\n\n### Details\nThe account settings page allows authenticated users to update their email address through a POST request. Unlike the login and password reset forms which implement reCAPTCHA and rate limiting protections, this endpoint lacks these safeguards entirely.\nAn attacker can capture the email update request (for example, using Burp Suite\u0027s proxy) and modify the email field to test arbitrary addresses. The panel\u0027s response will confirm whether each tested email is already registered in the system. Because there are no rate limits implemented, attackers can send hundreds or thousands of requests to enumerate the user base.\n\nThis is concerning because:\n\n- The login and password reset pages correctly implement protections against enumeration\n- The account page has no reCAPTCHA option available\n- No rate limiting exists in the panel for this endpoint\n- Authentication is required, but any valid account (including free tier/trial accounts) can exploit this\n\n### PoC\n- Log into the Pterodactyl panel with any valid account\n- Navigate to Account Settings\n- Open Burp Suite (or similar proxy tool) and configure your browser to proxy through it\n- Attempt to change your email address and capture the POST request\n- Send the captured request to Repeater\n- Modify the email field to test different addresses (e.g., admin@example.com, test@example.com)\n- Send multiple requests in rapid succession\n- Observe the response messages which confirm whether each email exists or not \n- Repeat indefinitely without encountering rate limits or CAPTCHA challenges\n\n\n### Impact\nThis is a user enumeration vulnerability (CWE-204: Observable Response Discrepancy).\n\nWho is impacted:\n\n- All Pterodactyl panel installations are affected\n- Any registered user\u0027s email address can be discovered\n- Particularly impacts administrators and high-value accounts\n\nPotential consequences:\n\n- Attackers can build a complete database of registered users\n- Enumerated emails can be used for targeted phishing campaigns\n- Combined with other attacks (credential stuffing, social engineering)\n- Privacy violation for all users on the platform\n- Competitive intelligence gathering (identifying which companies/individuals use specific panels)",
"id": "GHSA-j7f5-gfqm-pcx3",
"modified": "2026-06-26T20:54:38Z",
"published": "2026-06-26T20:54:38Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/pterodactyl/panel/security/advisories/GHSA-j7f5-gfqm-pcx3"
},
{
"type": "PACKAGE",
"url": "https://github.com/pterodactyl/panel"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P",
"type": "CVSS_V4"
}
],
"summary": "Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system"
}
GHSA-J7QG-8R9M-WXM8
Vulnerability from github – Published: 2022-08-24 00:00 – Updated: 2022-08-27 00:00All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.
{
"affected": [],
"aliases": [
"CVE-2022-1989"
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-08-23T10:15:00Z",
"severity": "MODERATE"
},
"details": "All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.",
"id": "GHSA-j7qg-8r9m-wxm8",
"modified": "2022-08-27T00:00:49Z",
"published": "2022-08-24T00:00:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1989"
},
{
"type": "WEB",
"url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=17142\u0026token=a3696ab41fef800d2eaee8043d40d5fbe94277fd\u0026download="
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-JC64-QJC6-H5VP
Vulnerability from github – Published: 2025-03-28 15:31 – Updated: 2025-03-28 15:31User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
{
"affected": [],
"aliases": [
"CVE-2025-2910"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-28T13:15:41Z",
"severity": "MODERATE"
},
"details": "User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.",
"id": "GHSA-jc64-qjc6-h5vp",
"modified": "2025-03-28T15:31:56Z",
"published": "2025-03-28T15:31:56Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2910"
},
{
"type": "WEB",
"url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-fermax-mobile-applications"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-JCVH-6RQ4-C7XR
Vulnerability from github – Published: 2022-06-23 00:00 – Updated: 2022-07-01 00:01A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.
{
"affected": [],
"aliases": [
"CVE-2022-31248"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-06-22T10:15:00Z",
"severity": "MODERATE"
},
"details": "A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to discover valid usernames. This issue affects: SUSE Manager Server 4.1 spacewalk-java versions prior to 4.1.46-1. SUSE Manager Server 4.2 spacewalk-java versions prior to 4.2.37-1.",
"id": "GHSA-jcvh-6rq4-c7xr",
"modified": "2022-07-01T00:01:15Z",
"published": "2022-06-23T00:00:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31248"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1199629"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-JFH6-W7R2-RJ74
Vulnerability from github – Published: 2026-08-25 03:32 – Updated: 2026-08-25 03:32Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/sendForgotPasswordEmail, and it triggers a password reset message for any address that matches an account. With no DDPRateLimiter rule registered for it, a caller can drive an unbounded volume of reset mail at a chosen address from the deployment's own mail sender, and can probe addresses at scale: the method answers true for an address with no account and for a successful send, but false when the address belongs to an account that authenticates through an external provider and Accounts_AllowPasswordChangeForOAuthUsers is off, so repeated calls distinguish that class of account. Later versions register a rule permitting ten calls per minute per client address.
{
"affected": [],
"aliases": [
"CVE-2026-75575"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-25T02:16:51Z",
"severity": "MODERATE"
},
"details": "Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/sendForgotPasswordEmail, and it triggers a password reset message for any address that matches an account. With no DDPRateLimiter rule registered for it, a caller can drive an unbounded volume of reset mail at a chosen address from the deployment\u0027s own mail sender, and can probe addresses at scale: the method answers true for an address with no account and for a successful send, but false when the address belongs to an account that authenticates through an external provider and Accounts_AllowPasswordChangeForOAuthUsers is off, so repeated calls distinguish that class of account. Later versions register a rule permitting ten calls per minute per client address.",
"id": "GHSA-jfh6-w7r2-rj74",
"modified": "2026-08-25T03:32:10Z",
"published": "2026-08-25T03:32:10Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-7c6v-m68v-v73r"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75575"
},
{
"type": "WEB",
"url": "https://github.com/RocketChat/Rocket.Chat/commit/3a61c3afe"
},
{
"type": "WEB",
"url": "https://github.com/RocketChat/Rocket.Chat"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/rocket-chat-missing-ddp-rate-limit-on-the-sendforgotpasswordemail-meteor-method"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-JGC6-C9V8-VFQW
Vulnerability from github – Published: 2024-07-01 18:32 – Updated: 2024-07-01 18:32In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance when they attempt to log in. This disclosure could then lead to additional brute-force password-guessing attacks. This vulnerability would require that the Splunk platform instance uses the Security Assertion Markup Language (SAML) authentication scheme.
{
"affected": [],
"aliases": [
"CVE-2024-36996"
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-01T17:15:08Z",
"severity": "MODERATE"
},
"details": "In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance when they attempt to log in. This disclosure could then lead to additional brute-force password-guessing attacks. This vulnerability would require that the Splunk platform instance uses the Security Assertion Markup Language (SAML) authentication scheme.",
"id": "GHSA-jgc6-c9v8-vfqw",
"modified": "2024-07-01T18:32:41Z",
"published": "2024-07-01T18:32:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36996"
},
{
"type": "WEB",
"url": "https://advisory.splunk.com/advisories/SVD-2024-0716"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-JHH7-832H-F8HV
Vulnerability from github – Published: 2026-07-31 22:24 – Updated: 2026-07-31 22:24Summary
The sendPasswordResetEmail mutation in WPGraphQL is explicitly designed to prevent user enumeration. The resolver in src/Mutation/SendPasswordResetEmail.php states in a code comment:
// We obsfucate the actual success of this mutation to prevent user enumeration.
The mutation always returns success: true regardless of whether the supplied username/email belongs to an existing user. The intended public output field is only success: Boolean.
However, a deprecated user field is still registered on the SendPasswordResetEmailPayload output type in src/Deprecated.php (lines 433-450). This deprecated field resolves to a full User object when the supplied username/email corresponds to an existing author-class user, and null otherwise — completely undermining the anti-enumeration design.
The @todo remove in 3.0.0 comment acknowledges the field is scheduled for removal, but it remains active in all 2.x releases, including current 2.14.1.
Discovered via source code review on May 29, 2026.
Details
The mutation resolver in src/Mutation/SendPasswordResetEmail.php:
$payload = ['success' => true, 'id' => null];
$user_data = self::get_user_data($input['username']);
if (!$user_data) {
graphql_debug(...);
return $payload; // id stays null
}
// ...send email, then...
return ['id' => $user_data->ID, 'success' => true];
The intended public output field is only success. The id is internal-only state for downstream resolvers.
src/Deprecated.php registers an additional user field on the same payload type:
register_graphql_field(
'SendPasswordResetEmailPayload',
'user',
[
'type' => 'User',
'deprecationReason' => static function () { return __('This field will be removed...'); },
'resolve' => static function ($payload, $args, AppContext $context) {
return !empty($payload['id'])
? $context->get_loader('user')->load_deferred($payload['id'])
: null;
},
],
);
This field reads the internal $payload['id'] and resolves it through the standard user loader. The User Model's allowed_restricted_fields policy permits unauthenticated reads of public author fields (databaseId, name, firstName, lastName, slug, description, uri, url).
PoC
mutation EnumerateUser {
sendPasswordResetEmail(input: { username: "victim@example.com" }) {
success
user {
databaseId
name
firstName
lastName
slug
description
uri
}
}
}
Behavior:
- Non-existing user/email → data.sendPasswordResetEmail.user is null
- - Existing author-class user → data.sendPasswordResetEmail.user is a full User object with the listed fields populated
- - success always returns true, preserving the appearance of obfuscation — the deprecated user field is the leak
Impact
- Username/email enumeration: unauthenticated attacker can verify whether any username or email is registered, with no WPGraphQL-side rate limiting
-
- Profile disclosure for author-class users: for any user with published posts (including editors and administrators), the attacker obtains
databaseId,name,firstName,lastName,slug,description(user bio),uri— substantially more than mere existence
- Profile disclosure for author-class users: for any user with published posts (including editors and administrators), the attacker obtains
-
- Bypasses partial hardening: sites that disabled the REST API user endpoint, the user XML sitemap, and
?author=Nauthor redirects may still be vulnerable through this WPGraphQL path
- Bypasses partial hardening: sites that disabled the REST API user endpoint, the user XML sitemap, and
-
- Spearphishing setup: firstName/lastName/description for authors provides personalized phishing material
Recommended fix
Either remove the deprecated user field entirely (advance the existing @todo remove in 3.0.0) or change the resolver to always return null:
diff
'resolve' => static function ($payload, $args, AppContext $context) {
- return !empty($payload['id']) ? $context->get_loader('user')->load_deferred($payload['id']) : null;
- + // Always null — this deprecated field previously leaked user existence,
- + // undermining the anti-enumeration design of the sendPasswordResetEmail mutation.
- + return null;
- },
-
Defense in depth — change the mutation resolver itself to not populate $payload['id'] on real success:
diff
return [
- 'id' => $user_data->ID,
- + 'id' => null,
- 'success' => true,
- ];
-
Luke Granto — independent security researcher operating in good faith. Discovery via source code review of wp-graphql/wp-graphql v2.14.1, approximately 15 minutes from git clone to confirmed bug. No live exploitation against any third-party deployment.
{
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "wp-graphql/wp-graphql"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-54768"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-31T22:24:29Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "## Summary\n\nThe `sendPasswordResetEmail` mutation in WPGraphQL is explicitly designed to prevent user enumeration. The resolver in `src/Mutation/SendPasswordResetEmail.php` states in a code comment:\n\n`// We obsfucate the actual success of this mutation to prevent user enumeration.`\n\nThe mutation always returns `success: true` regardless of whether the supplied username/email belongs to an existing user. The intended public output field is only `success: Boolean`.\n\nHowever, a deprecated `user` field is still registered on the `SendPasswordResetEmailPayload` output type in `src/Deprecated.php` (lines 433-450). This deprecated field resolves to a full `User` object when the supplied username/email corresponds to an existing author-class user, and `null` otherwise \u2014 completely undermining the anti-enumeration design.\n\nThe `@todo remove in 3.0.0` comment acknowledges the field is scheduled for removal, but it remains active in all 2.x releases, including current 2.14.1.\n\nDiscovered via source code review on May 29, 2026.\n\n## Details\n\nThe mutation resolver in `src/Mutation/SendPasswordResetEmail.php`:\n\n```php\n$payload = [\u0027success\u0027 =\u003e true, \u0027id\u0027 =\u003e null];\n$user_data = self::get_user_data($input[\u0027username\u0027]);\nif (!$user_data) {\n graphql_debug(...);\n return $payload; // id stays null\n}\n// ...send email, then...\nreturn [\u0027id\u0027 =\u003e $user_data-\u003eID, \u0027success\u0027 =\u003e true];\n```\n\nThe intended public output field is only `success`. The `id` is internal-only state for downstream resolvers.\n\n`src/Deprecated.php` registers an additional `user` field on the same payload type:\n\n```php\nregister_graphql_field(\n \u0027SendPasswordResetEmailPayload\u0027,\n \u0027user\u0027,\n [\n \u0027type\u0027 =\u003e \u0027User\u0027,\n \u0027deprecationReason\u0027 =\u003e static function () { return __(\u0027This field will be removed...\u0027); },\n \u0027resolve\u0027 =\u003e static function ($payload, $args, AppContext $context) {\n return !empty($payload[\u0027id\u0027])\n ? $context-\u003eget_loader(\u0027user\u0027)-\u003eload_deferred($payload[\u0027id\u0027])\n : null;\n },\n ],\n);\n```\n\nThis field reads the internal `$payload[\u0027id\u0027]` and resolves it through the standard user loader. The User Model\u0027s `allowed_restricted_fields` policy permits unauthenticated reads of public author fields (`databaseId`, `name`, `firstName`, `lastName`, `slug`, `description`, `uri`, `url`).\n\n## PoC\n\n```graphql\nmutation EnumerateUser {\n sendPasswordResetEmail(input: { username: \"victim@example.com\" }) {\n success\n user {\n databaseId\n name\n firstName\n lastName\n slug\n description\n uri\n }\n }\n}\n```\n\nBehavior:\n- Non-existing user/email \u2192 `data.sendPasswordResetEmail.user` is `null`\n- - Existing author-class user \u2192 `data.sendPasswordResetEmail.user` is a full User object with the listed fields populated\n- - `success` always returns `true`, preserving the appearance of obfuscation \u2014 the deprecated `user` field is the leak\n## Impact\n\n1. **Username/email enumeration:** unauthenticated attacker can verify whether any username or email is registered, with no WPGraphQL-side rate limiting\n2. 2. **Profile disclosure for author-class users:** for any user with published posts (including editors and administrators), the attacker obtains `databaseId`, `name`, `firstName`, `lastName`, `slug`, `description` (user bio), `uri` \u2014 substantially more than mere existence\n3. 3. **Bypasses partial hardening:** sites that disabled the REST API user endpoint, the user XML sitemap, and `?author=N` author redirects may still be vulnerable through this WPGraphQL path\n4. 4. **Spearphishing setup:** firstName/lastName/description for authors provides personalized phishing material\n## Recommended fix\n\nEither remove the deprecated `user` field entirely (advance the existing `@todo remove in 3.0.0`) or change the resolver to always return `null`:\n\n```diff\n\u0027resolve\u0027 =\u003e static function ($payload, $args, AppContext $context) {\n- return !empty($payload[\u0027id\u0027]) ? $context-\u003eget_loader(\u0027user\u0027)-\u003eload_deferred($payload[\u0027id\u0027]) : null;\n- + // Always null \u2014 this deprecated field previously leaked user existence,\n- + // undermining the anti-enumeration design of the sendPasswordResetEmail mutation.\n- + return null;\n- },\n- ```\nDefense in depth \u2014 change the mutation resolver itself to not populate `$payload[\u0027id\u0027]` on real success:\n\n```diff\nreturn [\n- \u0027id\u0027 =\u003e $user_data-\u003eID,\n- + \u0027id\u0027 =\u003e null,\n- \u0027success\u0027 =\u003e true,\n- ];\n- ```\n\nLuke Granto \u2014 independent security researcher operating in good faith. Discovery via source code review of wp-graphql/wp-graphql v2.14.1, approximately 15 minutes from `git clone` to confirmed bug. No live exploitation against any third-party deployment.",
"id": "GHSA-jhh7-832h-f8hv",
"modified": "2026-07-31T22:24:29Z",
"published": "2026-07-31T22:24:29Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv"
},
{
"type": "PACKAGE",
"url": "https://github.com/wp-graphql/wp-graphql"
},
{
"type": "WEB",
"url": "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)"
}
GHSA-JRJQ-9CMF-3H6F
Vulnerability from github – Published: 2026-08-04 15:32 – Updated: 2026-08-05 21:31In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
{
"affected": [],
"aliases": [
"CVE-2026-60007"
],
"database_specific": {
"cwe_ids": [
"CWE-204"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-04T13:18:55Z",
"severity": "CRITICAL"
},
"details": "In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim\u0027s `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim\u0027s password, and authenticate with the recovered credentials.",
"id": "GHSA-jrjq-9cmf-3h6f",
"modified": "2026-08-05T21:31:34Z",
"published": "2026-08-04T15:32:22Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60007"
},
{
"type": "WEB",
"url": "https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fb"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/183"
},
{
"type": "WEB",
"url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation MIT-46
Strategy: Separation of Privilege
- Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area.
- Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.
Mitigation MIT-39
- Ensure that error messages only contain minimal details that are useful to the intended audience and no one else. The messages need to strike the balance between being too cryptic (which can confuse users) or being too detailed (which may reveal more than intended). The messages should not reveal the methods that were used to determine the error. Attackers can use detailed information to refine or optimize their original attack, thereby increasing their chances of success.
- If errors must be captured in some detail, record them in log messages, but consider what could occur if the log messages can be viewed by attackers. Highly sensitive information such as passwords should never be saved to log files.
- Avoid inconsistent messaging that might accidentally tip off an attacker about internal state, such as whether a user account exists or not.
CAPEC-331: ICMP IP Total Length Field Probe
An adversary sends a UDP packet to a closed port on the target machine to solicit an IP Header's total length field value within the echoed 'Port Unreachable" error message. This type of behavior is useful for building a signature-base of operating system responses, particularly when error messages contain other types of information that is useful identifying specific operating system responses.
CAPEC-332: ICMP IP 'ID' Field Error Message Probe
An adversary sends a UDP datagram having an assigned value to its internet identification field (ID) to a closed port on a target to observe the manner in which this bit is echoed back in the ICMP error message. This allows the attacker to construct a fingerprint of specific OS behaviors.
CAPEC-541: Application Fingerprinting
An adversary engages in fingerprinting activities to determine the type or version of an application installed on a remote target.
CAPEC-580: System Footprinting
An adversary engages in active probing and exploration activities to determine security information about a remote target system. Often times adversaries will rely on remote applications that can be probed for system configurations.