{"id":"CVE-2026-27480","aliases":["GHSA-qhp6-635j-x7r2"],"url":"https://o3.security/vulnerability/CVE-2026-27480","summary":"Static Web Server: Timing-Based Username Enumeration in Basic Authentication","details":"Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by exploiting early responses for invalid usernames, enabling targeted brute-force or credential-stuffing attacks. SWS checks whether a username exists before verifying the password, causing valid usernames to follow a slower code path (e.g., bcrypt hashing) while invalid usernames receive an immediate 401 response. This timing discrepancy allows attackers to enumerate valid accounts by measuring response-time differences. This issue has been fixed in version 2.41.0.","published":"2026-02-21T09:14:30.376Z","modified":"2026-07-15T01:49:10.706425301Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"static-web-server","fixedVersion":"2.41.0"}],"fix":{"url":"https://github.com/static-web-server/static-web-server/commit/7bf0fd425eb10dac9bf9ef5febce12c4dd039ce1","label":"static-web-server/static-web-server@7bf0fd4"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27480.json"},{"type":"ADVISORY","url":"https://github.com/static-web-server/static-web-server/security/advisories/GHSA-qhp6-635j-x7r2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27480"},{"type":"FIX","url":"https://github.com/static-web-server/static-web-server/commit/7bf0fd425eb10dac9bf9ef5febce12c4dd039ce1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:10.706425301Z"}}