GHSA-8fxq-53rx-ph5f
### Summary `userpassword.Compare()` substituted a placeholder hash derived from the well-known string `"hunter2"` when the stored hash was empty. Submitting `"hunter2"` therefore matched accounts with no password hash (nonexistent users and SSO-only users) and a subsequent login-type check returned an HTTP 403 that disclosed the account's login type, versus 401 for password users. > **Note:** Practical exploitation is limited because the timing side channel is noisy and only reveals whether an account exists. ### Impact An unauthenticated attacker could enumerate valid accounts and their authentication provider by submitting logins with the password `"hunter2"`, distinguishing nonexistent users, SSO users (provider revealed) and password users from the response. This aids credential-stuffing and targeted phishing. No authentication bypass or data access resulted. ### Patches The fix derives the timing-defense placeholder from a secure random value that no supplied password can match. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds None. ### References - Fix: #26205 ### Credits We'd like to thank Anthropic's Security Team (ANT-2026-22433) for independently disclosing this issue!
Properties
- ghsa_id
- GHSA-8fxq-53rx-ph5f
- summary
- Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
- severity
- low
- cvss_score
- 3.7
- cve_id
- GHSA-8fxq-53rx-ph5f
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-08-20T18:34:21Z
- source_url
- https://github.com/advisories/GHSA-8fxq-53rx-ph5f
- ghsa_updated
- 2026-08-20T18:34:23Z
Related Entities (5)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph