GHSA-7g89-3w9x-xw88MediumCVSS 3.7

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.

🔗 References (6)