<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T04:00:40.137686+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335342</id>
    <title>EUVD-2026-335342</title>
    <updated>2026-10-07T04:00:40.257197+00:00</updated>
    <content>EUVD-2026-335342</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44332</id>
    <title>fkie_cve-2026-44332</title>
    <updated>2026-10-07T04:00:40.257239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g5vh-55hw-rxm8</id>
    <title>GHSA-g5vh-55hw-rxm8 — GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer</title>
    <updated>2026-10-07T04:00:40.257287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gofiber/fiber/v3</p>
<p>## Summary</p>
<p>The default `Authorizer` function in GoFiber's BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.</p>
<p>## Vulnerable Code</p>
<p>**File:** `middleware/basicauth/config.go`, lines 126-138</p>
<p>```go
if cfg.Authorizer == nil {
    verifiers := make(map[string]func(string) bool, len(cfg.Users))
    for u, hpw := range cfg.Users {
        v, err := parseHashedPassword(hpw)
        if err != nil {
            panic(err)
        }
        verifiers[u] = v
    }
    cfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {
        verify, ok := verifiers[user]
        return ok &amp;&amp; verify(pass)   // line 137: short-circuit skips verify() if user unknown
    }
}
```</p>
<p>## Data Flow</p>
<p>1. Attacker sends `Authorization: Basic &lt;base64(candidate:wrongpass)&gt;`
2. BasicAuth middleware decodes credentials and calls `cfg.Authorizer(user, pass, c)`
3. Map lookup `verifiers[user]` returns `ok=false` for non-existent users
4. Go `&amp;&amp;` short-circuit: `false &amp;&amp; verify(pass)` returns immediately without calling `verify()`
5. For valid users, `verify(pass)` executes `bcrypt.CompareHashAndPassword()` (line 167: ~100ms at default cost 10)
6. Timing difference: ~100ns (invalid user) vs ~100ms (valid user) = 1,000,000:1 ratio</p>
<p>**Timing comp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g5vh-55hw-rxm8"/>
  </entry>
</feed>
