CWE-208

CWE-208 · 7 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-208, highest CVSS first.

  1. MEDIUM 5.9CVE-2026-85725public PoC

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after the first mismatching byt…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.3CVE-2026-58272public PoC

    Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accounts return without perf…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.7CVE-2026-95270public PoC

    A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable tim…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-63132public PoC

    OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to m…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-77987public PoC

    A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing requests to be directed to in…

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-88010public PoC

    Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concurrent requests for absen…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-77582public PoC

    Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler a…

    AI risk analysis on Exploit-DB.ai →