CVE Explorer
CVE-2026-23892
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that short-circuits on the first mismatched character during API key validation, rather than a cryptographical method with static runtime regardless of the point of mismatch, an attacker with network based access to an affected Octo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"OctoPrint","vendor":"OctoPrint","versions":[{"status":"affected","version":"< 1.11.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":6,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-208","description":"CWE-208: Observable Timing Discrepancy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/OctoPrint/OctoPrint/commit/249fd80ab01bc4b7dabedff768230a0fb5d01a8c","tags":["x_refsource_MISC"],"url":"https://github.com/OctoPrint/OctoPrint/commit/249fd80ab01bc4b7dabedff768230a0fb5d01a8c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/references/1
{"name":"https://github.com/OctoPrint/OctoPrint/releases/tag/1.11.6","tags":["x_refsource_MISC"],"url":"https://github.com/OctoPrint/OctoPrint/releases/tag/1.11.6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/references/2
{"name":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-xg4x-w2j3-57h6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-xg4x-w2j3-57h6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9cf0dcc418d78303b71cb85e672d6ef1411895240767b8b25c53b82253e6ba9b · sha256:aa2433d995cc96b6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.