OSV 1.4.0 · github-reviewed · 修改于 2026-07-02 21:46
发布时间
2026-07-02 21:46
GitHub 审查时间
2026-07-02 21:46
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-g5vh-55hw-rxm8/GHSA-g5vh-55hw-rxm8.json
The default Authorizer function in GoFiber's BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords (the primary use case), the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration.
File: middleware/basicauth/config.go, lines 126-138
if cfg.Authorizer == nil {
verifiers := make(map[string]func(string) bool, len(cfg.Users))
for u, hpw := range cfg.Users {
v, err := parseHashedPassword(hpw)
if err != nil {
panic(err)
}
verifiers[u] = v
}
cfg.Authorizer = func(user, pass string, _ fiber.Ctx) bool {
verify, ok := verifiers[user]
return ok && verify(pass) // line 137: short-circuit skips verify() if user unknown
}
}
Authorization: Basic <base64(candidate:wrongpass)>cfg.Authorizer(user, pass, c)verifiers[user] returns ok=false for non-existent users&& short-circuit: false && verify(pass) returns immediately without calling verify()verify(pass) executes bcrypt.CompareHashAndPassword() (line 167: ~100ms at default cost 10)Timing comparison by hash type:
| Hash Type | Valid User | Invalid User | Ratio |
|---|---|---|---|
| bcrypt ($2) | ~100 ms | ~100 ns | 1,000,000:1 |
| SHA-512 | ~1-5 us | ~100 ns | 10-50:1 |
| SHA-256 | ~1-5 us |
| ~100 ns |
| 10-50:1 |
subtle.ConstantTimeCompare is used correctly for SHA-256 (line 185), SHA-512 (line 176), and bcrypt uses its own constant-time comparisonbcrypt.CompareHashAndPassword(dummyHash, []byte(pass)) and discard the result