Executive brief
Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames
Affected products
- crates.io static-web-server
Junglewise Threat Intelligence
CVE-2026-27480 · Severity: low · CVSS 3.1 · Published 2026-02-20
Technologies: static-web-server (crates.io). Vendors: crates.io.
Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames