{"id":"GHSA-5w46-g9pq-wh6f","summary":"Filament: Timing-based user enumeration on login page","details":"The login page has an observable timing discrepancy that allows unauthenticated attackers to enumerate registered email addresses. The impact is limited to disclosing whether an account exists for a given email.","aliases":["CVE-2026-48166"],"modified":"2026-09-10T03:50:48.544238932Z","published":"2026-06-23T21:54:35Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-23T21:54:35Z","nvd_published_at":"2026-06-22T22:16:46Z","cwe_ids":["CWE-208"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/filamentphp/filament/security/advisories/GHSA-5w46-g9pq-wh6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48166"},{"type":"PACKAGE","url":"https://github.com/filamentphp/filament"}],"affected":[{"package":{"name":"filament/filament","ecosystem":"Packagist","purl":"pkg:composer/filament/filament"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.11.5"}]}],"versions":["v4.0.0","v4.0.1","v4.0.10","v4.0.11","v4.0.12","v4.0.13","v4.0.14","v4.0.15","v4.0.16","v4.0.17","v4.0.18","v4.0.19","v4.0.2","v4.0.20","v4.0.3","v4.0.4","v4.0.5","v4.0.6","v4.0.7","v4.0.8","v4.0.9","v4.1.0","v4.1.1","v4.1.10","v4.1.2","v4.1.3","v4.1.4","v4.1.5","v4.1.6","v4.1.7","v4.1.8","v4.1.9","v4.10.0","v4.10.1","v4.10.2","v4.11.0","v4.11.1","v4.11.2","v4.11.3","v4.11.4","v4.2.0","v4.2.1","v4.2.2","v4.2.3","v4.2.4","v4.3.0","v4.3.1","v4.4.0","v4.5.0","v4.5.1","v4.5.2","v4.5.3","v4.6.0","v4.6.1","v4.6.2","v4.6.3","v4.7.0","v4.7.1","v4.7.2","v4.7.3","v4.7.4","v4.8.0","v4.8.1","v4.8.2","v4.8.3","v4.8.4","v4.8.5","v4.9.0","v4.9.1","v4.9.2","v4.9.3","v4.9.4","v4.9.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 4.11.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5w46-g9pq-wh6f/GHSA-5w46-g9pq-wh6f.json"}},{"package":{"name":"filament/filament","ecosystem":"Packagist","purl":"pkg:composer/filament/filament"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.6.5"}]}],"versions":["v5.0.0","v5.1.0","v5.1.1","v5.1.2","v5.1.3","v5.2.0","v5.2.1","v5.2.2","v5.2.3","v5.2.4","v5.3.0","v5.3.1","v5.3.2","v5.3.3","v5.3.4","v5.3.5","v5.4.0","v5.4.1","v5.4.2","v5.4.3","v5.4.4","v5.4.5","v5.5.0","v5.5.1","v5.5.2","v5.6.0","v5.6.1","v5.6.2","v5.6.3","v5.6.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.6.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-5w46-g9pq-wh6f/GHSA-5w46-g9pq-wh6f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}