{"id":"CVE-2022-40482","details":"The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\\Auth\\SessionGuard class when a user is found to not exist.","modified":"2026-08-12T03:51:22.448693060Z","published":"2023-04-25T00:00:00Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"8.x"},{"fixed":"9.x"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/40xxx/CVE-2022-40482.json"},"references":[{"type":"WEB","url":"https://github.com/laravel/framework/releases/tag/v9.32.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/40xxx/CVE-2022-40482.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-40482"},{"type":"FIX","url":"https://github.com/laravel/framework/pull/44069"},{"type":"PACKAGE","url":"https://github.com/ephort/laravel-user-enumeration-demo"},{"type":"ARTICLE","url":"https://ephort.dk/blog/laravel-timing-attack-vulnerability/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/laravel/framework","events":[{"introduced":"43bea00fd27c76c01fd009e46725a54885f4d2a5"},{"fixed":"a684da6197ae77eee090637ae4411b2f321adfc7"},{"introduced":"fbe7ed828819eadabb3cb9f95847a2ffe8846fd6"},{"fixed":"aae3b59f82434176546c9dd10804adda16da5278"}],"database_specific":{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.83.24"},{"introduced":"9.0.0"},{"fixed":"9.32.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*"}}],"versions":["v9.31.0","v9.30.1","v9.30.0","v9.29.0","v9.28.0","v9.27.0","v9.26.1","v9.26.0","v9.25.1","v9.25.0","v9.24.0","v9.23.0","v9.22.1","v9.22.0","v9.21.6","v9.21.5","v9.21.4","v9.21.3","v9.21.2","v9.21.1","v8.83.20","v9.21.0","v8.83.19","v9.20.0","v9.19.0","v8.83.18","v9.18.0","v8.83.17","v8.83.16","v9.17.0","v9.16.0","v9.15.0","v9.14.1","v8.83.14","v9.14.0","v8.83.13","v9.13.0","v9.12.2","v9.12.1","v8.83.12","v9.12.0","v8.83.11","v9.11.0","v9.10.1","v8.83.10","v9.10.0","v9.9.0","v8.83.9","v8.83.8","v9.8.1","v9.8.0","v8.83.7","v9.7.0","v9.6.0","v8.83.5","v9.5.1","v9.5.0","v9.4.1","v8.83.4","v9.4.0","v8.83.3","v9.3.1","v9.3.0","v9.2.0","v8.83.2","v8.83.1","v9.1.0","v8.83.0","v9.0.2","v9.0.1","v9.0.0","v8.82.0","v8.81.0","v8.78.0","v8.77.1","v8.77.0","v8.76.2","v8.75.0","v8.74.0","v8.73.2","v8.73.1","v8.73.0","v8.72.0","v8.71.0","v8.70.2","v8.70.1","v8.70.0","v8.68.0","v8.67.0","v8.66.0","v8.65.0","v8.64.0","v8.63.0","v8.62.0","v8.61.0","v8.60.0","v8.59.0","v8.58.0","v8.57.0","v8.56.0","v8.55.0","v8.54.0","v8.53.1","v8.53.0","v8.52.0","v8.51.0","v8.50.0","v8.49.2","v8.49.1","v8.49.0","v8.48.2","v8.48.1","v8.48.0","v8.47.0","v8.46.0","v8.45.1","v8.45.0","v8.44.0","v8.43.0","v8.42.1","v8.42.0","v8.41.0","v8.40.0","v8.38.0","v8.36.0","v8.35.1","v8.35.0","v8.33.0","v8.32.1","v8.32.0","v8.31.0","v8.30.0","v8.30.1","v8.29.0","v8.28.1","v8.28.0","v8.27.0","v8.26.1","v8.26.0","v8.25.0","v8.24.0","v8.23.1","v8.23.0","v8.22.1","v8.22.0","v8.21.0","v8.20.1","v8.20.0","v8.19.0","v8.17.2","v8.17.1","v8.17.0","v8.16.0","v8.15.0","v8.14.0","v8.13.0","v8.12.3","v8.12.2","v8.12.1","v8.12.0","v8.11.2","v8.11.0","v8.11.1","v8.9.0","v8.8.0","v8.7.1","v8.7.0","v8.6.0","v8.5.0","v8.4.0","v8.3.0","v8.2.0","v8.1.0","v8.0.4","v8.0.3","v8.0.2","v8.0.1","v8.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-40482.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}