Medium severity5.3NVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026
CVE-2026-54685
CVE-2026-54685
Description
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the /api/auth/login authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a 401/403 response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gtsteffaniak/filebrowser/backendGo | < 0.0.0-20260317230626-af08800667b8 | 0.0.0-20260317230626-af08800667b8 |
Affected products
2- Range: <1.3.2-beta
- Range: <1.3.2-beta
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.