Timing Discrepancy Vulnerability in Gophish by Gophish Inc.
CVE-2026-107269
Key Information:
Badges
What is CVE-2026-107269?
Gophish version 0.12.1 is susceptible to a timing discrepancy vulnerability in the AdminServer.Login component. This security flaw enables unauthenticated attackers to exploit the response time discrepancies during the login process to enumerate valid usernames. By submitting various candidate usernames via the POST request to /login, attackers can detect delays caused by the bcrypt comparison for existing accounts, thereby honing in on potential targets for subsequent password guessing or credential stuffing attacks. It is crucial for users managing Gophish to implement mitigations and ensure their systems remain secure against such enumeration tactics.
Affected Version(s)
gophish 0 <= 0.12.1
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
