CVE-2026-107269 PUBLISHED

Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy

Assigner: VulnCheck
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor gophish
Product gophish
Versions Default: unaffected
  • affected from 0 to 0.12.1 (incl.)

Credits

  • Sohaib Harraoui (Ostorlab) finder

References

Problem Types

  • Observable Timing Discrepancy CWE