<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T09:21:09.591965+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-270429</id>
    <title>EUVD-2026-270429</title>
    <updated>2026-10-07T09:21:09.638965+00:00</updated>
    <content>EUVD-2026-270429</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-270429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27480</id>
    <title>fkie_cve-2026-27480</title>
    <updated>2026-10-07T09:21:09.639006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by exploiting early responses for invalid usernames, enabling targeted brute-force or credential-stuffing attacks. SWS checks whether a username exists before verifying the password, causing valid usernames to follow a slower code path (e.g., bcrypt hashing) while invalid usernames receive an immediate 401 response. This timing discrepancy allows attackers to enumerate valid accounts by measuring response-time differences. This issue has been fixed in version 2.41.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qhp6-635j-x7r2</id>
    <title>GHSA-qhp6-635j-x7r2 — Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invali…</title>
    <updated>2026-10-07T09:21:09.639044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: static-web-server</p>
<p>## Summary</p>
<p>A Timing-based username enumeration in Basic Authentication vulnerability due to early response on invalid usernames could allow attackers to identify valid users and focus their efforts on targeted brute-force or credential-stuffing attacks.</p>
<p>## Details</p>
<p>SWS validates the provided username before performing any password verification.
- **Invalid Username:** The server returns a `401 Unauthorized` response immediately.
- **Valid Username:** The server proceeds to verify the password (e.g., using `bcrypt`), which introduces a different execution path and measurable timing discrepancy.</p>
<p>This allows an attacker to distinguish between existing and non-existing accounts by analyzing response times.</p>
<p>## PoC</p>
<p>The following statistical results were obtained by measuring the mean response time over 100 iterations using a custom Rust script:</p>
<p>| User Type | Average Response Time |
| :--- | :--- |
| **Invalid User** | 0.409861 ms |
| **Valid User** | 0.250925 ms |
| **Difference** | **~0.158936 ms** |</p>
<p>While the valid user responded faster in this specific test environment, the statistically significant gap confirms that the authentication logic does not execute in constant time.</p>
<p>## Impact</p>
<p>Users using the SWS' Basic Authentication feature are primarily impacted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qhp6-635j-x7r2"/>
  </entry>
</feed>
