Medium severity5.9NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10535
CVE-2016-10535
Description
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses ===, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the timing attack not present.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
csrf-litenpm | < 0.1.2 | 0.1.2 |
Affected products
3- cpe:2.3:a:csrf-lite_project:csrf-lite:*:*:*:*:*:node.js:*:*Range: <=0.1.1
- HackerOne/csrf-lite node modulev5Range: <=0.1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-hjhr-r3gq-qvp6ghsaADVISORY
- github.com/isaacs/csrf-lite/pull/1nvdThird Party AdvisoryWEB
- nodesecurity.io/advisories/94nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2016-10535ghsaADVISORY
- www.npmjs.com/advisories/94ghsaWEB
News mentions
0No linked articles in our index yet.