VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 35 of 39
  • CVE-2003-0078Mar 3, 2003
    risk 0.04cvss epss 0.14

    ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely…

  • CVE-2001-1528Dec 31, 2001
    risk 0.04cvss epss 0.08

    AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.

  • CVE-2023-1998MedApr 21, 2023
    risk 0.03cvss 5.6epss 0.01

    The Linux kernel allows userspace processes to enable mitigations by calling prctl with PR_SET_SPECULATION_CTRL which disables the speculation feature as well as by using seccomp. We had noticed that on VMs of at least one major cloud provider, the kernel still left the victim…

  • CVE-2026-67193MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol…

  • CVE-2026-64713HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.

  • CVE-2026-65314MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions…

  • CVE-2026-64822MedJul 21, 2026
    risk 0.00cvss 5.3epss 0.00

    djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct error messages returned by the password reset…

  • CVE-2026-56339HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error…

  • CVE-2026-56296MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing error message…

  • CVE-2026-58503MedJul 10, 2026
    risk 0.00cvss epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed in versions 16.16.0 and 15.106.0.

  • CVE-2026-51926HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can…

  • CVE-2026-44332MedJul 8, 2026
    risk 0.00cvss 5.3epss 0.00

    Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable…

  • CVE-2026-56327MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function…

  • CVE-2026-21484MedJan 3, 2026
    risk 0.00cvss 5.3epss 0.01

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username…

  • CVE-2025-13912LowDec 11, 2025
    risk 0.00cvss epss 0.00

    Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, which can potentially result in observable timing discrepancies and lead to information disclosure through timing side-channel attacks.

  • CVE-2025-39665MedDec 3, 2025
    risk 0.00cvss 5.3epss 0.00

    User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.

  • CVE-2025-12888HigNov 21, 2025
    risk 0.00cvss 7.5epss 0.00

    Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architecture limitations, specifically with the Xtensa-based ESP32 chips. If targeting Xtensa it is recommended to use the low memory…

  • CVE-2025-11932MedNov 21, 2025
    risk 0.00cvss 4.3epss 0.00

    The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

  • CVE-2025-57770MedAug 22, 2025
    risk 0.00cvss 5.3epss 0.00

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Versions 4.0.0 to 4.0.2, 3.0.0 to 3.3.6, and all versions prior to 2.71.15 are vulnerable to a username enumeration issue in the login interface. The login UI…

  • CVE-2025-52576MedJun 25, 2025
    risk 0.00cvss 5.3epss 0.00

    Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force protection bypass. By analyzing login behavior and abusing trusted HTTP headers, an attacker…