CWE-203— Observable Discrepancy (Information Exposure via Side Channel)
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.— MITRE CWE catalog
769 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-203page 16 of 16
- CVE-2026-4040MEDIUMCVSS 5.5EG 5.52026-03-12
A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs t…
- CVE-2026-4045LOWCVSS 3.7EG 3.72026-03-12
A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be ex…
- CVE-2026-41588CRITICALCVSS 9.0EG 9.02026-05-08
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
- CVE-2026-44263MEDIUMCVSS 4.3EG 4.32026-05-07
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.1…
- CVE-2026-44332MEDIUMCVSS 5.3EG 5.32026-07-02
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for n…
- CVE-2026-45294MEDIUMCVSS 5.3EG 5.32026-05-29
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing us…
- CVE-2026-45410MEDIUMCVSS 5.3EG 5.32026-05-28
TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, th…
- CVE-2026-47011LOWCVSS 2.6EG 2.62026-07-21
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface). Supported versions that are affected are 17.0-26.4. Difficult to exploit vulnerability allows low privileged attacker with network…
- CVE-2026-47379MEDIUMCVSS 6.9EG 6.92026-06-05
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back to strict-equality (===) comparison for legacy plaintext passwords, leaking the password's length and per-character pre…
- CVE-2026-51926HIGHCVSS 7.5EG 7.52026-07-09
An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the log…
- CVE-2026-56296MEDIUMCVSS 5.3EG 5.32026-07-11
Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid ap…
- CVE-2026-56316MEDIUMCVSS 5.3EG 5.32026-06-21
Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. Atta…
- CVE-2026-56319MEDIUMCVSS 4.3EG 4.32026-06-20
Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling app IDs through differential error responses. Attackers can…
- CVE-2026-56327MEDIUMCVSS 5.3EG 5.32026-07-01
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers…
- CVE-2026-56339HIGHCVSS 7.5EG 7.52026-07-15
Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existen…
- CVE-2026-58503MEDIUMCVSS 6.9EG 6.92026-07-10
Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.
- CVE-2026-64822MEDIUMCVSS 5.3EG 5.32026-07-21
djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct error mes…
- CVE-2026-65314MEDIUMCVSS 4.3EG 4.32026-07-21
Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can o…
- CVE-2026-8242LOWCVSS 3.7EG 3.72026-05-10
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy. The…
Map vulnerabilities like CWE-203 to your infrastructure
EchelonGraph correlates every CVE — across CWE-203 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →