{"id":"CVE-2026-54685","summary":"FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel","details":"FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time. Version 1.3.2-beta patches the issue.","aliases":["GHSA-7789-65hx-f26w","GO-2026-4820"],"modified":"2026-08-12T03:51:48.801427243Z","published":"2026-07-20T14:17:13.083Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54685.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-208"]},"references":[{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.2-beta"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54685.json"},{"type":"ADVISORY","url":"https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54685"},{"type":"FIX","url":"https://github.com/gtsteffaniak/filebrowser/commit/af08800667b874620edc6f44c3e2e64fec7abd85"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gtsteffaniak/filebrowser","events":[{"introduced":"0"},{"fixed":"af08800667b874620edc6f44c3e2e64fec7abd85"},{"fixed":"19d60a8a2410ff4e0cbb7a9cfc723be0a2b91e41"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.3.2-beta"}]}}],"versions":["v1.2.1-stable","v1.0.1-stable","v0.7.6-beta","v0.5.2-beta","v0.5.1-beta","v0.5.0-beta","v0.4.2-beta","v0.4.1-beta","v0.4.0-beta","v0.3.7-beta","v0.3.6-beta","v0.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54685.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}