Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler). Because the token-submission endpoint (taskReset) also lacks rate limiting, an attacker could in principle send repeated token guesses against a known username and use the timing differences to attempt to recover a valid token, though the vendor rates the practical exploitability as low and no end-to-end network exploit has been demonstrated. | |
| Title | Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison | |
| First Time appeared |
Getgrav
Getgrav grav |
|
| Weaknesses | CWE-208 | |
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav
Getgrav grav |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:22.914Z
Reserved: 2026-08-10T13:02:20.829Z
Link: CVE-2026-72700
No data.
Status : Received
Published: 2026-08-25T02:16:45.830
Modified: 2026-08-25T02:16:45.830
Link: CVE-2026-72700
No data.
OpenCVE Enrichment
Updated: 2026-08-25T04:30:05Z
-
CWE-208
Observable Timing Discrepancy