CVE Explorer
CVE-2026-45410
TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an email address existed in the database, the backend performed a bcrypt password comparison before returning a 401 Unauthorized, adding ~370 ms of latency. When the email did not exist, the backend returned immediately (~10 ms). This ~14× timing difference could be detected without any difference in HTT
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-203","description":"CWE-203: Observable Discrepancy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-208","description":"CWE-208: Observable Timing Discrepancy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"TREK","vendor":"mauriceboe","versions":[{"status":"affected","version":"< 3.0.18"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-203","description":"CWE-203: Observable Discrepancy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-208","description":"CWE-208: Observable Timing Discrepancy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://gist.github.com/jubnl/c2402adf85d946c1730867aeecc794de","tags":["x_refsource_MISC"],"url":"https://gist.github.com/jubnl/c2402adf85d946c1730867aeecc794de"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/references/1
{"name":"https://github.com/mauriceboe/TREK/security/advisories/GHSA-3552-3c98-x79r","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mauriceboe/TREK/security/advisories/GHSA-3552-3c98-x79r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/mauriceboe/TREK/security/advisories/GHSA-3552-3c98-x79r"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b78d99c8e1325eb4793667039ebb1e21d30512a44eb2d89dfcd9d48061c2a235 · sha256:5b20e7fbaf5ef930… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.