Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107269

LOW NVD
CVSS Score 3.7
Severity LOW
Published Oct 07, 2026
Vendor unknown

Description

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.

References