Loading HuntDB...

GHSA-rpv4-63g3-9x23

GitHub Security Advisory

Radicale is vulnerable to timing oracles and simple bruteforce attacks

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Radicale before 1.1.2 and 2.0.0rc1 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.

Affected Packages

PyPI Radicale
Affected versions: 0 (fixed in 1.1.2)
PyPI Radicale
Affected versions: 2.0.0rc1 (fixed in 2.0.0rc2)

Related CVEs

Key Information

GHSA ID
GHSA-rpv4-63g3-9x23
Published
May 13, 2022 1:27 AM
Last Modified
October 16, 2024 9:22 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
Radicale
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.