Medium severity5.3NVD Advisory· Published Apr 25, 2023· Updated Jun 17, 2026
CVE-2022-40482
CVE-2022-40482
Description
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/laravel/framework/pull/44069nvdPatchVendor Advisory
- ephort.dk/blog/laravel-timing-attack-vulnerability/nvdExploitTechnical DescriptionThird Party Advisory
- github.com/laravel/framework/releases/tag/v9.32.0nvdRelease Notes
News mentions
0No linked articles in our index yet.