Information Exposure Through Timing Discrepancy in Etherpad - #VU151599
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to conduct timing attacks against login credentials.
The vulnerability exists due to an observable timing discrepancy in the OIDC interaction login password comparison when processing login attempts. A remote attacker can measure password comparison timing to conduct timing attacks against login credentials.