Username Enumeration Vulnerability in Static Web Server by Static Web Server Team
CVE-2026-27480

5.3MEDIUM

Key Information:

Vendor
CVE Published:
21 February 2026

What is CVE-2026-27480?

A timing-based vulnerability exists in certain versions of Static Web Server, allowing attackers to exploit discrepancies in response times during Basic Authentication. This flaw enables malicious actors to pinpoint valid usernames by analyzing the varying response times generated when invalid usernames are inputted. Since the server processes valid usernames through a more time-consuming code path, attackers can initiate targeted brute-force or credential-stuffing attacks. This particular issue has been addressed in version 2.41.0.

Affected Version(s)

static-web-server >= 2.1.0, < 2.41.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.