CWE-208: CWE-208
Yearly Trend
Top Affected Vendors
All CWE-208 CVEs (26)
This vulnerability in RustCrypto CMOV allows timing side-channel attacks on cryptographic operations when using the thumbv6m-none-eabi compiler target...
Jan 15, 2026CVE-2021-43298 is a timing attack vulnerability in GoAhead web server's HTTP Basic authentication implementation. Attackers can brute-force passwords ...
Jan 25, 2022This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting a flaw in the Kerberos authentication proto...
Aug 13, 2024This vulnerability in NVIDIA DGX H100 and A100 BMC's host KVM daemon allows unauthenticated attackers to steal session tokens via timing side-channel ...
Sep 20, 2023This vulnerability in @fastify/bearer-auth allows attackers to perform timing attacks to estimate valid bearer token lengths, reducing the search spac...
Jul 14, 2022A timing attack vulnerability in third-party components of Siemens RUGGEDCOM industrial networking devices could allow attackers to retrieve private e...
Mar 8, 2022A critical timing attack vulnerability in Trilium Notes allows unauthenticated remote attackers to recover authentication hashes through statistical t...
Feb 6, 2026This vulnerability in IBM Common Cryptographic Architecture allows remote attackers to perform timing attacks against ECDSA signature generation, pote...
Mar 11, 2025CVE-2025-54764 is a timing side-channel vulnerability in Mbed TLS that allows local attackers to potentially extract RSA private keys by measuring exe...
Oct 20, 2025OpenClaw versions before 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer authentication token...
Mar 5, 2026This vulnerability in Intel QAT Engine for OpenSSL allows attackers to infer sensitive information through timing side-channel attacks during cryptogr...
Nov 13, 2024A timing side-channel vulnerability in liboqs' Kyber key encapsulation mechanism allows local attackers to extract the entire ML-KEM 512 secret key th...
Jun 10, 2024A timing side-channel vulnerability in HBUS devices allows attackers with physical access to extract cryptographic keys through timing analysis. This ...
Nov 18, 2025PrestaShop versions before 8.2.4 and 9.0.3 have a time-based user enumeration vulnerability in authentication that allows attackers to determine if cu...
Feb 6, 2026This vulnerability in Django's mod_wsgi authentication handler allows attackers to determine valid usernames via timing attacks by measuring response ...
Feb 3, 2026This vulnerability reintroduces timing attack risks in Spring Security's DaoAuthenticationProvider, allowing attackers to infer valid usernames throug...
Jan 22, 2026This CVE describes a timing attack vulnerability in File Browser's authentication mechanism that allows unauthenticated attackers to enumerate valid u...
Jan 19, 2026Mbed TLS versions through 3.6.4 contain a timing side-channel vulnerability in RSA decryption with PKCS#1 v1.5 padding. This allows attackers to poten...
Oct 21, 2025Dragonfly's proxy access control mechanism prior to version 2.1.0 uses simple string comparisons vulnerable to timing attacks. Attackers can guess pas...
Sep 17, 2025This CVE describes a username enumeration vulnerability in Liferay Portal and DXP where attackers can determine if user accounts exist by analyzing se...
Aug 21, 2025This vulnerability allows attackers to determine whether specific usernames exist in OpenSlides systems by measuring response time differences during ...
Mar 21, 2025This vulnerability allows unauthenticated attackers to determine valid usernames in Fides privacy platform by measuring timing differences in authenti...
Sep 4, 2024This vulnerability in Matrix libolm's AES implementation allows attackers to perform cache-timing attacks to potentially extract cryptographic keys. I...
Aug 22, 2024This vulnerability allows remote attackers to bypass authentication in OpenFUN Richie LMS by exploiting timing differences in HMAC signature verificat...
Feb 25, 2026FastAPI API Key version 1.1.0 has a timing side-channel vulnerability in verify_key() that allows attackers to statistically distinguish valid from in...
Jan 21, 2026This CVE describes an observable timing discrepancy vulnerability in Apache Shiro authentication. Attackers can use timing differences to distinguish ...
Feb 10, 2026About CWE-208 (CWE-208)
Our database tracks 26 CVEs classified as CWE-208, with 2 rated critical and 5 rated high severity. The average CVSS score for CWE-208 vulnerabilities is 6.1.
External reference: View CWE-208 on MITRE CWE →
Monitor CWE-208 Vulnerabilities
Get alerted when new CWE-208 CVEs affect your infrastructure.
Start Monitoring Free