PT-2026-5007 · Octoprint · Octoprint

Yueyuel

·

Publicado

2026-01-27

·

Atualizado

2026-02-02

·

CVE-2026-23892

CVSS v4.0

6.0

Média

VetorAV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions up to and including 1.11.5
Description OctoPrint, a web interface for controlling 3D printers, is affected by a timing attack that could allow an attacker with network access to extract API keys. The issue stems from the use of character-based comparison during API key validation, which short-circuits on the first mismatched character. This results in a non-constant runtime, potentially revealing information about the key through response time measurements. The likelihood of successful exploitation is dependent on network conditions such as latency and noise. A proof of concept has not been achieved, but the potential for API key extraction exists. The API key validation process is vulnerable to timing attacks. The denied access responses are used to guess API key characters.
Recommendations Versions prior to 1.11.6 should be updated to version 1.11.6 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23892
GHSA-XG4X-W2J3-57H6

Produtos afetados

Octoprint