SB2026072460 - Information Exposure Through Timing Discrepancy in hono
Published: July 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-56764)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable timing discrepancies in basicAuth and bearerAuth middlewares when comparing authentication hash values during request processing. A remote attacker can send authentication attempts and measure response timing differences to disclose sensitive information.
Exploitation is only theoretically possible under highly controlled conditions where precise timing measurements are possible.
Remediation
Install update from vendor's website.