lowCVSS 3.7Vulnerability

GHSA-8fxq-53rx-ph5f

### Summary `userpassword.Compare()` substituted a placeholder hash derived from the well-known string `"hunter2"` when the stored hash was empty. Submitting `"hunter2"` therefore matched accounts with no password hash (nonexistent users and SSO-only users) and a subsequent login-type check returned an HTTP 403 that disclosed the account's login type, versus 401 for password users. > **Note:** Practical exploitation is limited because the timing side channel is noisy and only reveals whether an account exists. ### Impact An unauthenticated attacker could enumerate valid accounts and their authentication provider by submitting logins with the password `"hunter2"`, distinguishing nonexistent users, SSO users (provider revealed) and password users from the response. This aids credential-stuffing and targeted phishing. No authentication bypass or data access resulted. ### Patches The fix derives the timing-defense placeholder from a secure random value that no supplied password can match. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### References - Fix: #26205 ### Credits We'd like to thank Anthropic's Security Team (ANT-2026-22433) for independently disclosing this issue!

Properties

ghsa_id
GHSA-8fxq-53rx-ph5f
summary
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
severity
low
cvss_score
3.7
cve_id
GHSA-8fxq-53rx-ph5f
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-08-20T18:34:21Z
source_url
https://github.com/advisories/GHSA-8fxq-53rx-ph5f
ghsa_updated
2026-08-20T18:34:23Z

Related Entities (5)

HAS_WEAKNESS (2)

[Weakness]Observable Response Discrepancy
[Weakness]Observable Discrepancy

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/coder/coder/v2

AFFECTS (1)

[Software]go/github.com/coder/coder/v2

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8fxq-53rx-ph5f (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal