{"id":"GO-2026-4820","summary":"FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend","details":"FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel in github.com/gtsteffaniak/filebrowser/backend","aliases":["CVE-2026-54685","GHSA-7789-65hx-f26w"],"modified":"2026-07-08T17:56:10.957994202Z","published":"2026-03-26T20:33:02Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4820"},"references":[{"type":"ADVISORY","url":"https://github.com/gtsteffaniak/filebrowser/security/advisories/GHSA-7789-65hx-f26w"},{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/commit/af08800667b874620edc6f44c3e2e64fec7abd85"},{"type":"WEB","url":"https://github.com/gtsteffaniak/filebrowser/releases/tag/v1.3.2-beta"}],"affected":[{"package":{"name":"github.com/gtsteffaniak/filebrowser/backend","ecosystem":"Go","purl":"pkg:golang/github.com/gtsteffaniak/filebrowser/backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260317230626-af08800667b8"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4820.json"}}],"schema_version":"1.7.5"}