SB2026072460 - Information Exposure Through Timing Discrepancy in hono



SB2026072460 - Information Exposure Through Timing Discrepancy in hono

Published: July 24, 2026

Security Bulletin ID SB2026072460
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-56764)

CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to observable timing discrepancies in basicAuth and bearerAuth middlewares when comparing authentication hash values during request processing. A remote attacker can send authentication attempts and measure response timing differences to disclose sensitive information.

Exploitation is only theoretically possible under highly controlled conditions where precise timing measurements are possible.


Remediation

Install update from vendor's website.