{"id":"CVE-2024-47178","aliases":["GHSA-7p89-p6hx-q4fw"],"url":"https://o3.security/vulnerability/CVE-2024-47178","summary":"basic-auth-connect's callback uses time unsafe string comparison","details":"basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.","published":"2024-09-30T15:09:59.513Z","modified":"2026-08-12T03:51:21.580893844Z","cvss":null,"epss":{"score":0.00522,"percentile":0.43121,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"basic-auth-connect","fixedVersion":"1.1.0"}],"fix":{"url":"https://github.com/expressjs/basic-auth-connect/commit/bac1e6a8530e1efd0028800b9b588a37adb0d203","label":"expressjs/basic-auth-connect@bac1e6a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47178.json"},{"type":"ADVISORY","url":"https://github.com/expressjs/basic-auth-connect/security/advisories/GHSA-7p89-p6hx-q4fw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47178"},{"type":"FIX","url":"https://github.com/expressjs/basic-auth-connect/commit/bac1e6a8530e1efd0028800b9b588a37adb0d203"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.580893844Z"}}