CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 14 of 16
- CVE-2024-50383MEDIUMCVSS 5.9EG 5.92024-10-23
Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was …
- CVE-2024-5124HIGHCVSS 7.5EG 7.52024-06-06
A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the …
- CVE-2024-51477MEDIUMCVSS 4.3EG 4.32025-03-29
IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.
- CVE-2024-51739HIGHCVSS 7.5EG 7.52024-11-05
Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer …
- CVE-2024-54002MEDIUMCVSS 5.3EG 5.32024-12-04
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the syst…
- CVE-2024-54454MEDIUMCVSS 5.3EG 5.32024-12-27
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. An Observable Response Discrepancy vulnerability in the sendPasswordReinitLink action of the unlogged.do page allo…
- CVE-2024-54476MEDIUMCVSS 5.5EG 5.52024-12-12
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.
- CVE-2024-54767HIGHCVSS 7.5EG 7.52025-01-06
An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and …
- CVE-2024-55374MEDIUMCVSS 5.3EG 5.32026-01-02
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
- CVE-2024-56738MEDIUMCVSS 5.3EG 5.32024-12-29
GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.
- CVE-2024-5690MEDIUMCVSS 4.3EG 4.32024-06-11
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- CVE-2024-5697MEDIUMCVSS 4.3EG 4.32024-06-11
A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.
- CVE-2024-6056LOWCVSS 3.7EG 3.72024-06-17
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulat…
- CVE-2024-6129LOWCVSS 3.7EG 3.72024-06-18
A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavi…
- CVE-2024-7010HIGHCVSS 5.9EG 7.52024-10-29
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic algorithms. Specifically, in the contex…
- CVE-2024-7881MEDIUMCVSS 5.1EG 5.12025-01-28
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.
- CVE-2024-8651MEDIUMCVSS 5.3EG 5.32024-09-19
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.241…
- CVE-2024-8992MEDIUMCVSS 4.0EG 4.02024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-8993MEDIUMCVSS 6.2EG 6.22024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-8994MEDIUMCVSS 6.2EG 6.22024-12-26
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- CVE-2024-9398MEDIUMCVSS 5.3EG 5.32024-10-01
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox…
- CVE-2024-9513LOWCVSS 3.7EG 3.72024-10-04
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/api/Answer/ReturnUserQuestionsFilled of the component HTTP PO…
- CVE-2025-0361MEDIUMCVSS 4.3EG 4.32025-04-08
During an annual penetration test conducted on behalf of Axis Communications, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed for unauthenticated username enumeration through the VAPIX Device Configuratio…
- CVE-2025-10890CRITICALCVSS 9.1EG 9.12025-09-24
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-11145HIGHCVSS 7.5EG 7.52025-10-24
Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Software Hardware Electronic Computer Systems Industry and Trad…
- CVE-2025-11443LOWCVSS 3.7EG 3.72025-10-08
A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepancy.…
- CVE-2025-11932MEDIUMCVSS 4.3EG 4.32025-11-21
The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder
- CVE-2025-12888HIGHCVSS 7.5EG 7.52025-11-21
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it i…
- CVE-2025-13912LOWCVSS 1.0EG 1.02025-12-11
Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosu…
- CVE-2025-1396LOWCVSS 3.7EG 3.72025-09-26
A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the vali…
- CVE-2025-1468HIGHCVSS 7.5EG 7.52025-03-18
An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.
- CVE-2025-21336MEDIUMCVSS 5.6EG 5.62025-01-14
Windows Cryptographic Information Disclosure Vulnerability
- CVE-2025-21510HIGHCVSS 7.5EG 7.52025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2025-23182MEDIUMCVSS 4.3EG 4.32025-05-22
CWE-203: Observable Discrepancy
- CVE-2025-24011MEDIUMCVSS 5.3EG 5.32025-01-21
Umbraco is a free and open source .NET content management system. Starting in version 14.0.0 and prior to versions 14.3.2 and 15.1.2, it's possible to determine whether an account exists based on an analysis of response codes and timing of…
- CVE-2025-24023LOWCVSS 3.7EG 3.72025-03-03
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This …
- CVE-2025-24391MEDIUMCVSS 5.3EG 5.32025-07-14
A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addre…
- CVE-2025-24506MEDIUMCVSS 5.3EG 5.32025-01-30
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
- CVE-2025-27451MEDIUMCVSS 5.3EG 5.32025-07-03
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existi…
- CVE-2025-27667CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Administrative User Email Enumeration OVE-20230524-0011.
- CVE-2025-29780MEDIUMCVSS 5.8EG 5.82025-03-14
Post-Quantum Secure Feldman's Verifiable Secret Sharing provides a Python implementation of Feldman's Verifiable Secret Sharing (VSS) scheme. In versions 0.8.0b2 and prior, the `feldman_vss` library contains timing side-channel vulnerabili…
- CVE-2025-30344MEDIUMCVSS 5.3EG 5.32025-03-21
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashin…
- CVE-2025-31124MEDIUMCVSS 5.3EG 5.32025-03-31
Zitadel is open-source identity infrastructure software. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to guess/enumerate usernames. If enabled, ZITADEL will show the …
- CVE-2025-32789LOWCVSS 3.1EG 3.12025-04-16
EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the pa…
- CVE-2025-36225MEDIUMCVSS 4.3EG 4.32025-10-09
IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data.
- CVE-2025-3939MEDIUMCVSS 5.3EG 5.32025-05-22
Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before…
- CVE-2025-39665MEDIUMCVSS 5.3EG 5.32025-12-03
User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.
- CVE-2025-39702HIGHCVSS 7.0EG 7.02025-09-05
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
- CVE-2025-40732HIGHCVSS 7.5EG 7.52025-06-30
user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php
- CVE-2025-41252HIGHCVSS 7.5EG 7.52025-09-29
Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration ��…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →