LOW
Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel
Published Apr 16, 2026
3.7
LOWCVSS 3.1
EPSS 0.31%
Description
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied username exists, returning immediately for nonexistent usernames. This timing discrepancy allows unauthenticated attackers to enumerate valid usernames by measuring response times, enabling targeted credential attacks. This issue has been fixed in version 0.19.2.
Affected products
-
- Version < 0.19.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/enchant97/note-mark/backend
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/enchant97/note-mark/backend | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23334 Advisory
- https://github.com/advisories/GHSA-w6m9-39cv-2fwp Advisory
- https://github.com/enchant97/note-mark/commit/cf4c6f6acf70b569d80396d323b067c00d45c034 x_refsource_MISC
- https://github.com/enchant97/note-mark/security/advisories/GHSA-w6m9-39cv-2fwp exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-40263
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23334 | Advisory | |
| https://github.com/advisories/GHSA-w6m9-39cv-2fwp | Advisory | |
| https://github.com/enchant97/note-mark/commit/cf4c6f6acf70b569d80396d323b067c00d45c034 | x_refsource_MISC | |
| https://github.com/enchant97/note-mark/security/advisories/GHSA-w6m9-39cv-2fwp | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40263 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 16, 2026
Updated Apr 17, 2026
Reserved Apr 10, 2026
Link CVE-2026-40263
CISA Vulnrichment
Updated Apr 17, 2026
ENISA EUVD
EUVD-2026-23334 GHSA-W6M9-39CV-2FWP Assigner GitHub_M
Published Apr 16, 2026
Updated Apr 17, 2026
Exploited since n/a
Link EUVD-2026-23334