CWE-208: CWE-208

26
Total CVEs
2
Critical
5
High
6.1
Avg CVSS

Yearly Trend

2026
10
2025
7
2024
5
2023
1
2022
3

Top Affected Vendors

1 Arm 2
2 Openquantumsafe 1
3 Openslides 1
4 Matrix 1
5 Djangoproject 1
6 Triliumnotes 1
7 Microsoft 1
8 Athroniaeth 1
9 Ibm 1
10 Embedthis 1

All CWE-208 CVEs (26)

CVE-2026-23519
9.8

This vulnerability in RustCrypto CMOV allows timing side-channel attacks on cryptographic operations when using the thumbv6m-none-eabi compiler target...

Jan 15, 2026
CVE-2021-43298
9.8

CVE-2021-43298 is a timing attack vulnerability in GoAhead web server's HTTP Basic authentication implementation. Attackers can brute-force passwords ...

Jan 25, 2022
CVE-2024-29995
8.1

This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting a flaw in the Kerberos authentication proto...

Aug 13, 2024
CVE-2023-25529
8.0

This vulnerability in NVIDIA DGX H100 and A100 BMC's host KVM daemon allows unauthenticated attackers to steal session tokens via timing side-channel ...

Sep 20, 2023
CVE-2022-31142
7.5

This vulnerability in @fastify/bearer-auth allows attackers to perform timing attacks to estimate valid bearer token lengths, reducing the search spac...

Jul 14, 2022
CVE-2021-42016
7.5

A timing attack vulnerability in third-party components of Siemens RUGGEDCOM industrial networking devices could allow attackers to retrieve private e...

Mar 8, 2022
CVE-2025-68621
7.4

A critical timing attack vulnerability in Trilium Notes allows unauthenticated remote attackers to recover authentication hashes through statistical t...

Feb 6, 2026
CVE-2024-22340
6.5

This vulnerability in IBM Common Cryptographic Architecture allows remote attackers to perform timing attacks against ECDSA signature generation, pote...

Mar 11, 2025
CVE-2025-54764
6.2

CVE-2025-54764 is a timing side-channel vulnerability in Mbed TLS that allows local attackers to potentially extract RSA private keys by measuring exe...

Oct 20, 2025
CVE-2026-28464
5.9

OpenClaw versions before 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attackers to infer authentication token...

Mar 5, 2026
CVE-2024-31074
5.9

This vulnerability in Intel QAT Engine for OpenSSL allows attackers to infer sensitive information through timing side-channel attacks during cryptogr...

Nov 13, 2024
CVE-2024-36405
5.9

A timing side-channel vulnerability in liboqs' Kyber key encapsulation mechanism allows local attackers to extract the entire ML-KEM 512 secret key th...

Jun 10, 2024
CVE-2025-52457
5.7

A timing side-channel vulnerability in HBUS devices allows attackers with physical access to extract cryptographic keys through timing analysis. This ...

Nov 18, 2025
CVE-2026-25597
5.3

PrestaShop versions before 8.2.4 and 9.0.3 have a time-based user enumeration vulnerability in authentication that allows attackers to determine if cu...

Feb 6, 2026
CVE-2025-13473
5.3

This vulnerability in Django's mod_wsgi authentication handler allows attackers to determine valid usernames via timing attacks by measuring response ...

Feb 3, 2026
CVE-2025-22234
5.3

This vulnerability reintroduces timing attack risks in Spring Security's DaoAuthenticationProvider, allowing attackers to infer valid usernames throug...

Jan 22, 2026
CVE-2026-23849
5.3

This CVE describes a timing attack vulnerability in File Browser's authentication mechanism that allows unauthenticated attackers to enumerate valid u...

Jan 19, 2026
CVE-2025-59438
5.3

Mbed TLS versions through 3.6.4 contain a timing side-channel vulnerability in RSA decryption with PKCS#1 v1.5 padding. This allows attackers to poten...

Oct 21, 2025
CVE-2025-59350
5.3

Dragonfly's proxy access control mechanism prior to version 2.1.0 uses simple string comparisons vulnerable to timing attacks. Attackers can guess pas...

Sep 17, 2025
CVE-2025-43754
5.3

This CVE describes a username enumeration vulnerability in Liferay Portal and DXP where attackers can determine if user accounts exist by analyzing se...

Aug 21, 2025
CVE-2025-30344
5.3

This vulnerability allows attackers to determine whether specific usernames exist in OpenSlides systems by measuring response time differences during ...

Mar 21, 2025
CVE-2024-45052
5.3

This vulnerability allows unauthenticated attackers to determine valid usernames in Fides privacy platform by measuring timing differences in authenti...

Sep 4, 2024
CVE-2024-45191
5.3

This vulnerability in Matrix libolm's AES implementation allows attackers to perform cache-timing attacks to potentially extract cryptographic keys. I...

Aug 22, 2024
CVE-2026-26717
4.8

This vulnerability allows remote attackers to bypass authentication in OpenFUN Richie LMS by exploiting timing differences in HMAC signature verificat...

Feb 25, 2026
CVE-2026-23996
3.7

FastAPI API Key version 1.1.0 has a timing side-channel vulnerability in verify_key() that allows attackers to statistically distinguish valid from in...

Jan 21, 2026
CVE-2026-23901
2.5

This CVE describes an observable timing discrepancy vulnerability in Apache Shiro authentication. Attackers can use timing differences to distinguish ...

Feb 10, 2026

About CWE-208 (CWE-208)

Our database tracks 26 CVEs classified as CWE-208, with 2 rated critical and 5 rated high severity. The average CVSS score for CWE-208 vulnerabilities is 6.1.

External reference: View CWE-208 on MITRE CWE →

Monitor CWE-208 Vulnerabilities

Get alerted when new CWE-208 CVEs affect your infrastructure.

Start Monitoring Free