Username Enumeration Vulnerability in Static Web Server by Static Web Server Team
CVE-2026-27480
5.3MEDIUM
What is CVE-2026-27480?
A timing-based vulnerability exists in certain versions of Static Web Server, allowing attackers to exploit discrepancies in response times during Basic Authentication. This flaw enables malicious actors to pinpoint valid usernames by analyzing the varying response times generated when invalid usernames are inputted. Since the server processes valid usernames through a more time-consuming code path, attackers can initiate targeted brute-force or credential-stuffing attacks. This particular issue has been addressed in version 2.41.0.
Affected Version(s)
static-web-server >= 2.1.0, < 2.41.0
