PT-2026-5007 · Octoprint · Octoprint

Yueyuel

·

Published

2026-01-27

·

Updated

2026-02-02

·

CVE-2026-23892

CVSS v4.0

6.0

Medium

VectorAV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions up to and including 1.11.5
Description OctoPrint, a web interface for controlling 3D printers, is affected by a timing attack that could allow an attacker with network access to extract API keys. The issue stems from the use of character-based comparison during API key validation, which short-circuits on the first mismatched character. This results in a non-constant runtime, potentially revealing information about the key through response time measurements. The likelihood of successful exploitation is dependent on network conditions such as latency and noise. A proof of concept has not been achieved, but the potential for API key extraction exists. The API key validation process is vulnerable to timing attacks. The denied access responses are used to guess API key characters.
Recommendations Versions prior to 1.11.6 should be updated to version 1.11.6 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-23892
GHSA-XG4X-W2J3-57H6

Affected Products

Octoprint