{"id":"CVE-2021-31404","details":"Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0.13 (Vaadin 10.0.0 through 10.0.16), 1.1.0 prior to 2.0.0 (Vaadin 11 prior to 14), 2.0.0 through 2.4.6 (Vaadin 14.0.0 through 14.4.6), 3.0.0 prior to 5.0.0 (Vaadin 15 prior to 18), and 5.0.0 through 5.0.2 (Vaadin 18.0.0 through 18.0.5) allows attacker to guess a security token via timing attack.","aliases":["GHSA-xwg3-qrcg-w9x6"],"modified":"2026-08-07T16:50:26.011486Z","published":"2021-04-23T16:15:08.647Z","references":[{"type":"ADVISORY","url":"https://vaadin.com/security/cve-2021-31404"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/9875"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/flow","events":[{"introduced":"3cd0c02025aba6de6fd78a8ea65c67483a721b4e"},{"fixed":"3a0bec8198b110458ccea3d5165de9d402817426"},{"introduced":"6b0da5b1d88e4541bebb4f26ef799b3f407bb74e"},{"fixed":"8e306579f157678c3baa3f3f63f406d073668161"},{"introduced":"8e306579f157678c3baa3f3f63f406d073668161"},{"fixed":"1442b1874678ad292e5b1250b7498ac99ecc4497"},{"introduced":"4b6ca4330163c4e976b32d03880fe2154a9d1ca7"},{"fixed":"60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"},{"introduced":"60b4fd8e59948e2a6a5f8af1988a3adc45563ffc"},{"fixed":"420a588d6072f3e6369fbc8439ac8d328b05d5d2"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:flow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"fixed":"1.0.14"},{"introduced":"1.1.0"},{"fixed":"2.0.0"},{"introduced":"2.0.0"},{"fixed":"2.4.7"},{"introduced":"3.0.0"},{"fixed":"5.0.0"},{"introduced":"5.0.0"},{"fixed":"5.0.3"}],"source":"CPE_RANGE"}}],"versions":["2.4.6","2.4.5","2.4.4","5.0.2","2.4.3","5.0.1","5.0.0","5.0.0.rc1","2.4.2","5.0.0.beta1","2.4.1","2.4.0","5.0.0.alpha1","2.4.0.beta2","2.4.0.beta1","2.4.0.alpha1","2.3.4","2.3.3","4.0.0.beta1","2.3.2","4.0.0.alpha3","2.3.1","4.0.0.alpha2","2.3.0","4.0.0.alpha1","2.3.0.beta3","2.3.0.beta2","3.2.0.alpha7","2.3.0.beta1","3.2.0.alpha6","3.2.0.alpha5","3.2.0.alpha4","2.3.0.alpha1","2.2.0.rc1","3.2.0.alpha3","2.2.0.beta2","3.2.0.alpha2","2.2.0.beta1","3.2.0.alpha1","2.2.0.alpha16","2.2.0.alpha15","2.2.0.alpha14","3.0.0.beta2","2.2.alpha14","3.0.0.beta4","3.0.0.beta3","2.2.0.alpha13","3.0.0.beta1","3.0.0.alpha17","2.2.0.alpha12","2.2.0.alpha11","2.2.0.alpha10","2.2.0.alpha9","2.2.0.alpha8","2.2.0.alpha7","2.2.0.alpha6","2.2.0.alpha5","2.2.0.alpha4","2.2.0.alpha3","2.2.0.alpha2","2.2.0.alpha1","2.1.0.beta3","3.0.0.alpha5","2.1.0.beta1","2.1.0.alpha1","1.0.13","2.0.8","2.0.7","2.0.6","1.0.12","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","2.0.0.rc3","1.0.11","2.0.0.rc2","2.0.0.rc1","2.0.0.beta2","2.0.0.beta1","2.0.0.alpha5","1.5.0.alpha4","1.5.0.alpha3","1.0.10","1.5.0.alpha2","1.5.0.alpha1","1.0.9","1.0.8","1.3.0.alpha3","1.3.0.alpha2","1.0.7","1.0.6","1.2.0","1.2.0.beta2","1.2.0.beta1","1.2.0.alpha1","1.1.0","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31404.json","vanir_signatures_modified":"2026-08-07T16:50:26Z","vanir_signatures":[{"id":"CVE-2021-31404-0d26ca84","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/test/java/com/vaadin/flow/internal/ResponseWriterTest.java","function":"assertMultipartResponse"},"deprecated":false,"digest":{"function_hash":"249622570144799160707345132873329528777","length":1300}},{"signature_version":"v1","source":"https://github.com/vaadin/flow/commit/3a0bec8198b110458ccea3d5165de9d402817426","target":{"file":"flow-server/src/main/java/com/vaadin/flow/server/communication/StreamReceiverHandler.java"},"deprecated":false,"digest":{"line_hashes":["133991899515961323250281832043496807197","249159474352653487934556951151599851894","240088532057232545644831235116762154793","270254788349579320055880890362721350995","69863386539325907529089889408700413500"],"threshold":0.9},"id":"CVE-2021-31404-0ee03c87","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["160937225051918761478269234930327001891","46889990866690041514682102058244386468","26363513694312015506855934224560524820","219833123941898919814816514009225503040"],"threshold":0.9},"id":"CVE-2021-31404-0f19a1e1","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/8e306579f157678c3baa3f3f63f406d073668161","target":{"file":"flow-server/src/main/java/com/vaadin/flow/server/frontend/FrontendDependencies.java"}},{"deprecated":false,"digest":{"line_hashes":["23295020156755417456129072944945494042","19013390935718152928276376341568950922","183287954718629551973592466569970766610"],"threshold":0.9},"id":"CVE-2021-31404-32c723e9","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/1442b1874678ad292e5b1250b7498ac99ecc4497","target":{"file":"flow-tests/test-root-context/src/test/java/com/vaadin/flow/uitest/ui/BrokenRouterLinkIT.java"}},{"deprecated":false,"digest":{"function_hash":"50889928194372581869835555549574839970","length":749},"id":"CVE-2021-31404-335b9616","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/420a588d6072f3e6369fbc8439ac8d328b05d5d2","target":{"file":"flow-tests/test-npm-only-features/test-npm-performance-regression/src/test/java/com/vaadin/flow/testnpmonlyfeatures/performanceregression/StartupPerformanceIT.java","function":"devModeInitializerToWebpackUpIsBelowThreshold"}},{"deprecated":false,"digest":{"line_hashes":["153177363219435303937481346278910453140","181422030205452905305290291040049227309","33971829593394412345599048598093718036","275041624494612527645552893294291103394","86469247458738357383103507442104737069","25922342559461617944053885903640254293","232339524840583842812333248918319678667"],"threshold":0.9},"id":"CVE-2021-31404-417a7d8e","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/test/java/com/vaadin/flow/internal/ResponseWriterTest.java"}},{"target":{"file":"flow-tests/test-npm-only-features/test-npm-performance-regression/src/test/java/com/vaadin/flow/testnpmonlyfeatures/performanceregression/StartupPerformanceIT.java"},"deprecated":false,"digest":{"line_hashes":["250495925707892314158189183523557768883","252475727024003677413540548807899597419","188406126592005394790782905052161347148","116462041464214745136812583121079315621"],"threshold":0.9},"id":"CVE-2021-31404-839dace8","signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/420a588d6072f3e6369fbc8439ac8d328b05d5d2"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/main/java/com/vaadin/flow/internal/ResponseWriter.java"},"deprecated":false,"digest":{"line_hashes":["43520808278726046006432504985646778166","296123810924565338498643766530874911587","221259991966709583237594580063444196171","108437677596457758235630426291300831986","317700053554754753249584371690674619316","161853292399189728664655237763082637062","27953669406768766753844549422154923759","271721621782024497285018147912205502689","97433726130074578806977607204725840712","153742533932158225961900960708720470033","275096766594378320841425464416028224121","106015272132669031337108147864651992326","172585572563459339251084935163900343552","118576641918442202000303694882491631629","159566678862912923854403932800634387798","250832752003912735365863795960963851311","95251104644391592641027354560185502492","285848104943858832560397642457555650382","315036448805680584430042212921432466215","255473002469754674093051837237214340125","230235063635031316715263929865930818925","322837197650918553560479406135892037458","74990952378373315520732252202114369521","315036448805680584430042212921432466215","80656763328939012405066971435088009862","184993245847957223953294561761420966511","27613114131117876128238304830026711186","310898117397158724705314868744425276684","211579530431730291031803728089338761891","155912885843459940685605779617059510580","99375202491282114146738158083936559773"],"threshold":0.9},"id":"CVE-2021-31404-a61406d4"},{"target":{"file":"flow-server/src/main/java/com/vaadin/flow/server/frontend/FrontendDependencies.java","function":"isVisitable"},"deprecated":false,"digest":{"function_hash":"332361481167583811488630660825504437087","length":276},"id":"CVE-2021-31404-dd8db9b6","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/8e306579f157678c3baa3f3f63f406d073668161"},{"deprecated":false,"digest":{"length":1587,"function_hash":"299806186407132363208599384657169049253"},"id":"CVE-2021-31404-e6f3accf","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/60b4fd8e59948e2a6a5f8af1988a3adc45563ffc","target":{"file":"flow-server/src/main/java/com/vaadin/flow/internal/ResponseWriter.java","function":"writeRangeContents"}},{"target":{"file":"flow-tests/test-root-context/src/test/java/com/vaadin/flow/uitest/ui/BrokenRouterLinkIT.java","function":"testRouterLink_visitBrokenLinkAndBack_scrollPositionIsRetained"},"deprecated":false,"digest":{"function_hash":"216146142699340666866805434489889519070","length":409},"id":"CVE-2021-31404-f3680331","signature_type":"Function","signature_version":"v1","source":"https://github.com/vaadin/flow/commit/1442b1874678ad292e5b1250b7498ac99ecc4497"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/platform","events":[{"introduced":"8e1b5f1a3f9bb984108d172f19d4d2df4a1987f5"},{"fixed":"0c357eed9a224c68a22005a4e3ac828bbeeac237"},{"introduced":"b1b5f755102e03fab90c511f4b207d394cbca8fb"},{"fixed":"1497812ad40b7ff90bef8bdb28808afc8d7194d1"},{"introduced":"1497812ad40b7ff90bef8bdb28808afc8d7194d1"},{"fixed":"8e32c64466482d39bb1f89232c1f0c267b9613a3"},{"introduced":"354ad0186b5e61b548adad84de03af297dc6f2a6"},{"fixed":"48b62a17fdbf3430bb83ab8653e937e34eea6c78"},{"introduced":"0f6048aefc10582e3042adb05064dac232f2f2c9"},{"fixed":"6bebc5a3d04b6ac892bf3801e3dd998442efa60b"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.0.0"},{"fixed":"10.0.17"},{"introduced":"11.0.0"},{"fixed":"14.0.0"},{"introduced":"14.0.0"},{"fixed":"14.4.7"},{"introduced":"15.0.0"},{"fixed":"17.0.0"},{"introduced":"18.0.0"},{"fixed":"18.0.6"}],"source":"CPE_RANGE"}}],"versions":["14.4.6","18.0.5","18.0.4","14.4.5","18.0.3","18.0.2","18.0.1","18.0.0","14.4.4","14.4.3","14.4.2","14.4.1","14.4.0","14.4.0.rc1","14.4.0.beta2","14.4.0.beta1","14.4.0.alpha1","17.0.0.rc2","17.0.0.rc1","17.0.0.beta3","17.0.0.beta2","17.0.0.beta1","17.0.0.alpha7","17.0.0.alpha6","16.0.1","14.3.0.rc1","14.3.0","14.3.0.beta3","17.0.0.alpha5","14.3.0.beta2","14.3.0.beta1","17.0.0.alpha4","17.0.0.alpha3","17.0.0.alpha2","14.3.0.alpha1","14.2.0","14.2.0.rc1","14.2.0.beta1","16.0.0.alpha3","16.0.0.alpha2","14.2.0.alpha11","16.0.0.alpha1","14.2.0.alpha10","14.2.0.alpha9","14.2.0.alpha8","14.2.0.alpha7","14.2.0.alpha6","15.0.0.rc1","15.0.0","14.2.0.alpha5","14.2.0.alpha4","14.2.0.alpha3","14.2.0.alpha2","14.2.0.alpha1","14.1.2","14.1.1","14.1.0","14.1.0.beta2","14.1.0.beta1","14.1.0.alpha3","14.1.0.alpha1","14.0.2","14.0.1","14.0.0","14.0.0.rc9","14.0.0.rc7","14.0.0.rc6","14.0.0.rc5","14.0.0.rc4","14.0.0.rc3","10.0.16","14.0.0.rc2","14.0.0.rc1","14.0.0.beta3","14.0.0.beta2","10.0.15","14.0.0.beta1","14.0.0.alpha4","10.0.14","10.0.13","14.0.0.alpha3","14.0.0.alpha2","10.0.12","14.0.0.alpha1","10.0.11","13.0.1","13.0.0","13.0.0.beta3","13.0.0.beta2","13.0.0.beta1","13.0.0.alpha4","13.0.0.alpha3","13.0.0.alpha2","10.0.10","13.0.0.alpha1","10.0.9","10.0.8","10.0.7","12.0.0.beta2","12.0.0.beta1","12.0.0.alpha5","12.0.0.alpha4","10.0.6","12.0.0.alpha3","12.0.0.alpha2","12.0.0.alpha1","10.0.5","10.0.4","10.0.3","11.0.0.beta1","11.0.0.alpha1","10.0.2","10.0.1","10.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31404.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/vaadin/vaadin","events":[{"introduced":"7ac406600a3c1a228e15ba253fe844f7e13771a0"},{"fixed":"e50e883d5ffce87431858dd57a37d7284dd19868"},{"introduced":"75cb16838a5b87c6e1a15b9e453e0d7c90cc1d53"},{"fixed":"ca9cf99092245a31a84b317adf1d79a397970d27"},{"introduced":"ca9cf99092245a31a84b317adf1d79a397970d27"},{"fixed":"1494745964f9df384b6fc63a6fd0214ee7b61efe"},{"introduced":"9efda1b1e0a27769eef9292dd7799d8fea77e633"},{"fixed":"f58e704f1d0c37efc6c00e604b4299000f7d5795"},{"introduced":"a5bc6b4832e649fb16243e2bc0ee9b2941815e3b"},{"fixed":"a2df3a561435ec90624f3ecdaa5d23dd10186b98"}],"database_specific":{"cpe":"cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"10.0.0"},{"fixed":"10.0.17"},{"introduced":"11.0.0"},{"fixed":"14.0.0"},{"introduced":"14.0.0"},{"fixed":"14.4.7"},{"introduced":"15.0.0"},{"fixed":"17.0.0"},{"introduced":"18.0.0"},{"fixed":"18.0.6"}],"source":"CPE_RANGE"}}],"versions":["v18.0.5","v14.4.0","v14.4.6","v14.4.5","v18.0.4","v18.0.3","v14.4.4","v18.0.2","v18.0.1","v18.0.0","v14.4.3","v14.4.2","v14.4.1","v14.4.0-rc1","v14.4.0-beta2","v14.4.0-beta1","v14.4.0-alpha1","v17.0.0-rc1","v14.3.0","v17.0.0-rc2","v17.0.0-beta3","v17.0.0-beta2","v17.0.0-beta1","v17.0.0-alpha7","v17.0.0-alpha6","v17.0.0-alpha5","v14.3.0-rc1","v14.3.0-beta3","v17.0.0-alpha4","v14.3.0-beta2","v14.3.0-beta1","v14.3.0-alpha1","v17.0.0-alpha3","v14.2.0","v17.0.0-alpha2","v17.0.0-alpha1","v16.0.0-alpha3","v14.2.0-rc1","v14.2.0-beta1","v14.2.0-alpha11","v16.0.0-alpha2","v16.0.0-alpha1","v14.2.0-alpha10","v15.0.0-rc1","v14.2.0-alpha9","v14.2.0-alpha8","v14.2.0-alpha7","v14.2.0-alpha6","v14.2.0-alpha5","v15.0.0-beta5","v14.2.0-alpha4","v15.0.0-beta4","v15.0.0-beta3","v15.0.0-beta2","v15.0.0-beta1","v14.2.0-alpha3","v15.0.0-alpha15","v15.0.0-alpha14","v15.0.0-alpha13","v15.0.0-alpha12","v15.0.0-alpha11","v14.2.0-alpha2","v15.0.0-alpha10","v14.2.0-alpha1","v14.1.2","v15.0.0-alpha9","v15.0.0-alpha8","v15.0.0-alpha7","v14.1.1","v15.0.0-alpha6","v15.0.0-alpha5","v14.1.0","v14.1.0-rc1","v15.0.0-alpha4","v14.1.0-beta3","v14.1.0-beta2","v14.1.0-beta1","v15.0.0-alpha3","v14.1.0-alpha5","v15.0.0-alpha2","v14.1.0-alpha4","v14.1.0-alpha3","v14.1.0-alpha2","v15.0.0-alpha1","v14.1.0-alpha1","v14.0.2","v10.0.16","v14.0.1","v14.0.0","v14.0.0-rc9","v14.0.0-rc8","v14.0.0-rc7","v14.0.0-rc6","v14.0.0-rc5","v14.0.0-rc4","v14.0.0-rc3","v14.0.0-rc2","v14.0.0-rc1","v14.0.0-beta3","v14.0.0-beta2","v10.0.15","v14.0.0-beta1","v14.0.0-alpha4","v14.0.0-alpha3","v10.0.14","v10.0.13","v14.0.0-alpha2","v14.0.0-alpha1","v10.0.12","v13.0.1","v10.0.11","v13.0.0","v13.0.0-beta3","v13.0.0-beta2","v10.0.10","v13.0.0-beta1","v13.0.0-alpha4","v13.0.0-alpha3","v13.0.0-alpha2","v13.0.0-alpha1","v10.0.9","v12.0.2","v12.0.1","v12.0.0","v12.0.0-beta2","v10.0.8","v10.0.7","v12.0.0-beta1","v10.0.6","v12.0.0-alpha5","v12.0.0-alpha4","v12.0.0-alpha3","v12.0.0-alpha2","v12.0.0-alpha1","v10.0.5","v10.0.4","v10.0.3","v10.0.2","v11.0.0-beta1","v11.0.0-alpha1","v10.0.1","v10.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31404.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}