GHSA-p6f7-72pm-r6j9MediumCVSS 3.7

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows...

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (1)

📋 Description

Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login throttling protection.

🔗 References (4)