CVE-2026-107269: Gophish
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.
Affected products
- Gophish Gophish: up to and including 0.12.1
Published 2026-10-07. Last modified 2026-10-10.