<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 02:57:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335342</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335342</link>
      <description>EUVD-2026-335342</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335342</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44332</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44332</link>
      <description>&lt;p&gt;Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enumeration through response timing differences. This issue is fixed in version 3.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44332</guid>
    </item>
    <item>
      <title>GHSA-g5vh-55hw-rxm8 — GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g5vh-55hw-rxm8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The default `Authorizer` function in GoFiber&amp;#39;s BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `middleware/basicauth/config.go`, lines 126-138&lt;/p&gt;
&lt;p&gt;```go
if cfg.Authorizer == nil {
    verifiers := make(map[string]func(string) bool, len(cfg.Users))
    for u, hpw := range cfg.Users {
        v, err := parseHashedPassword(hpw)
        if err != nil {
            panic(err)
        }
        verifiers[u] = v
    }
    cfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {
        verify, ok := verifiers[user]
        return ok &amp;amp;&amp;amp; verify(pass)   // line 137: short-circuit skips verify() if user unknown
    }
}
```&lt;/p&gt;
&lt;p&gt;## Data Flow&lt;/p&gt;
&lt;p&gt;1. Attacker sends `Authorization: Basic &amp;lt;base64(candidate:wrongpass)&amp;gt;`
2. BasicAuth middleware decodes credentials and calls `cfg.Authorizer(user, pass, c)`
3. Map lookup `verifiers[user]` returns `ok=false` for non-existent users
4. Go `&amp;amp;&amp;amp;` short-circuit: `false &amp;amp;&amp;amp; verify(pass)` returns immediately without calling `verify()`
5. For valid users, `verify(pass)` executes `bcrypt.CompareHashAndPassword()` (line 167: ~100ms at default cost 10)
6. Timing difference: ~100ns (invalid user) vs ~100ms (valid user) = 1,000,000:1 ratio&lt;/p&gt;
&lt;p&gt;**Timing comp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gofiber/fiber/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The default `Authorizer` function in GoFiber&amp;#39;s BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;**File:** `middleware/basicauth/config.go`, lines 126-138&lt;/p&gt;
&lt;p&gt;```go
if cfg.Authorizer == nil {
    verifiers := make(map[string]func(string) bool, len(cfg.Users))
    for u, hpw := range cfg.Users {
        v, err := parseHashedPassword(hpw)
        if err != nil {
            panic(err)
        }
        verifiers[u] = v
    }
    cfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {
        verify, ok := verifiers[user]
        return ok &amp;amp;&amp;amp; verify(pass)   // line 137: short-circuit skips verify() if user unknown
    }
}
```&lt;/p&gt;
&lt;p&gt;## Data Flow&lt;/p&gt;
&lt;p&gt;1. Attacker sends `Authorization: Basic &amp;lt;base64(candidate:wrongpass)&amp;gt;`
2. BasicAuth middleware decodes credentials and calls `cfg.Authorizer(user, pass, c)`
3. Map lookup `verifiers[user]` returns `ok=false` for non-existent users
4. Go `&amp;amp;&amp;amp;` short-circuit: `false &amp;amp;&amp;amp; verify(pass)` returns immediately without calling `verify()`
5. For valid users, `verify(pass)` executes `bcrypt.CompareHashAndPassword()` (line 167: ~100ms at default cost 10)
6. Timing difference: ~100ns (invalid user) vs ~100ms (valid user) = 1,000,000:1 ratio&lt;/p&gt;
&lt;p&gt;**Timing comp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g5vh-55hw-rxm8</guid>
    </item>
  </channel>
</rss>
