PT-2026-107566 · Gophish · Gophish
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gophish