Junglewise Threat Intelligence

CVE-2026-27480: Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames

CVE-2026-27480 · Severity: low · CVSS 3.1 · Published 2026-02-20

Technologies: static-web-server (crates.io). Vendors: crates.io.

Executive brief

Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames

Affected products

  • crates.io static-web-server

Related threats