GHSA-26xj-r8r2-vvgx
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 14, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.