Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Couch-auth exposes sensitive data through timing attacks

CVE-2025-70949 GHSA-mjqr-5c55-g77h GHSA-mjqr-5c55-g77h
Summary

The couch-auth library for authentication has a weakness that allows attackers to guess sensitive information by measuring how long it takes for the system to respond. This could lead to unauthorized access to sensitive data. Update to the latest version to fix this vulnerability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
perfood couch-auth <= 0.26.0
perfood @perfood/couch-auth <= 0.26.0
Original title
@perfood/couch-auth has an Observable Timing Discrepancy
Original description
An Observable Timing Discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.
nvd CVSS3.1 7.5
Vulnerability type
CWE-208
Published: 5 Mar 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026