← Back
CWE-203

751 CVEs • Abstraction: Base

Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

JSON object

Loading...

CVEs (751)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Answer
1Answer
Jun 17, 2026
Mar 21, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 21, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
1Ibexa
1Ez Platform Kernel
Jun 17, 2026
Mar 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.
1Amazon
2Opensearch
Opensearch Security
Jun 17, 2026
Mar 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists...Show more
OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls using the internal basic identity provider (IdP), and not other externally configured IdPs. Patches were released in versions 1.3.9 and 2.6.0, there are no workarounds.Show less
1Vantage6
1Vantage6
Jun 17, 2026
Mar 1, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt...Show more
vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This issue has been fixed in version 3.8.0. Show less
1Mozilla
2Firefox
Firefox Esr
Jun 17, 2026
Feb 16, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
5Debian
FedoraprojectGnu+2 more
7Active Iq Unified Manager
Converged Systems Advisor AgentDebian Linux+4 more
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.Show less
2Openssl
Stormshield
4Endpoint Security
OpensslSslvpn+1 more
Jun 17, 2026
Feb 8, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an at...Show more
A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.Show less
1Healthchecks
1Healthchecks
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.
1Jopenid Project
1Jopenid
Apr 3, 2025
Jan 18, 2023
N/A· v4
7.5 HIGH· v3
1.4 LOW· v2
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads t...Show more
A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/OpenIdManager.java. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.08 is able to address this issue. The name of the patch is c9baaa976b684637f0d5a50268e91846a7a719ab. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218460.Show less
1Redhat
2Jboss Enterprise Application Platform
Wildfly Elytron
Jun 17, 2026
Jan 13, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks...Show more
wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure information or impersonate an authed user.Show less
1Nvidia
1Dgx A100 Firmware
Jun 17, 2026
Jan 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.
1Tp Link
2Archer C5 Firmware
Tl Wr710n Firmware
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd proces...Show more
TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd process, an attacker could guess each byte of the username and password.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.
1Talend
1Administration Center
Jun 17, 2026
Jan 10, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any acco...Show more
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.Show less
1Arm
10Cortex A53 Firmware
Cortex A55 FirmwareCortex A57 Firmware+7 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are pos...Show more
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks. NOTE: the vendor reportedly offers the position "while power side channel attacks ... are possible, they are not directly caused by or related to the Arm architecture."Show less
1Paysafe
1Barzahlen Payment Module Php Sdk
Nov 21, 2024
Jan 8, 2023
N/A· v4
5.3 MEDIUM· v3
1.4 LOW· v2
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observabl...Show more
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 3e7d29dc0ca6c054a6d6e211f32dae89078594c1. It is recommended to upgrade the affected component. VDB-217650 is the identifier assigned to this vulnerability.Show less
1Google
1Chrome
Jun 17, 2026
Jan 2, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)
1Ziftrshop
1Primecoin
Nov 21, 2024
Jan 1, 2023
N/A· v4
7.5 HIGH· v3
1.4 LOW· v2
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUse...Show more
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUserPass/strRPCUserColonPass leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.8.4rc2 is able to address this issue. The patch is named cdb3441b5cd2c1bae49fae671dc4a496f7c96322. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217171.Show less
1Linuxcontainers
1Lxc
Jun 17, 2026
Jan 1, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does no...Show more
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons for failing except that the file does not exist.Show less