Executive brief
ApostropheCMS is a content management system used to build and manage websites. A flaw in its password reset feature allows unauthorized individuals to determine if a specific username or email address exists on the site by measuring how long the server takes to respond. This information can be used to target specific users for phishing or to prepare for more advanced account takeover attempts.
Technical details
The password reset endpoint (`/api/v1/@apostrophecms/login/reset-request`) in ApostropheCMS contains a timing side channel (CWE-208). While the application implements a fixed 2-second delay when a user is not found, it fails to normalize the timing when a user is found. In the 'user found' path, the system performs MongoDB updates and SMTP operations without an equivalent artificial delay, leading to measurable timing differences. An unauthenticated attacker can exploit this by sending automated requests and statistically analyzing response times to identify valid accounts. The vulnerability is present when the `passwordReset` option is enabled (it is disabled by default). Version 4.29.0 fixes this by ensuring all code paths adhere to a minimum response time.
Affected products
- ApostropheCMS apostrophe < 4.29.0
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Fixed in version 4.29.0
- 2026-04-16: advisory