VYPR
Moderate severityNVD Advisory· Published Jul 20, 2026· Updated Jul 21, 2026

FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel

CVE-2026-54685

Description

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the /api/auth/login authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a 401/403 response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/gtsteffaniak/filebrowser/backendGo
< 0.0.0-20260317230626-af08800667b80.0.0-20260317230626-af08800667b8

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.