Vulnerability GHSA-6f65-4fv2-wwch

Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
8 months ago
January 30, 2026 at 07:35 PM UTC
Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
0.1.0-alpha.1 - 3.5.3-master-202601300300
0.1.0-alpha.1 - 3.5.3-master-202601300300

Summary

Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy

Details

Summary

The NativeAuthenticationStrategy.authenticate() method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses).

Details

In packages/core/src/config/auth/native-authentication-strategy.ts, the authenticate method returns immediately if a user is not found:

const user = await this.userService.getUserByEmailAddress(ctx, data.username);
if (!user) {
    return false; // Instant return (~1-5ms)
}
const passwordMatch = await this.verifyUserPassword(ctx, user.id, data.password);
// Password check takes ~200-400ms with bcrypt (12 rounds)

The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts.

Impact

  • Attackers can enumerate valid user accounts
  • Enables targeted brute-force or phishing attacks
  • Information disclosure (account existence)

Recommended Fix

Perform a dummy bcrypt check when user is not found to ensure consistent response times.

Impacted packages

Timeline

Published
8 months ago
January 30, 2026 at 07:35 PM UTC
Fixed (3.5.3)
8 months ago
January 30, 2026 at 01:26 PM UTC
Last Modified
7 months ago
February 03, 2026 at 03:03 AM UTC