CVE-2026-107269: Gophish

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.

Affected products

  • Gophish Gophish: up to and including 0.12.1

Published 2026-10-07. Last modified 2026-10-10.