Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Volume of CVEs assigned to CWE-208 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
158 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47783HIGH In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_serv | May 20, 2026 | 8.1 | 37 | NO | NO |
CVE-2026-6656HIGH Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The check_password method uses the built-in eq operator. This allows discrepancies in timing to b | Jul 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-23519CRITICAL RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior | Jan 15, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-15432HIGH When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig inf | Jul 21, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-47373HIGH Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess | May 20, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-47784HIGH In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. | May 20, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-41588HIGH RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via c | May 8, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-40972HIGH An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this coul | Apr 28, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-13183HIGH In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling re | Jul 22, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-54736HIGH Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the attacker-supplied HMAC tag against the freshly computed HMA | Jul 10, 2026 | 8.2 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.