GHSA-6f65-4fv2-wwch
Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
Quick fix
GHSA-6f65-4fv2-wwch — @vendure/core: upgrade to the fixed version with the command below.
npm install @vendure/core@3.5.3Details
### Summary The `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses).
### Details In `packages/core/src/config/auth/native-authentication-strategy.ts`, the authenticate method returns immediately if a user is not found:
```typescript const user = await this.userService.getUserByEmailAddress(ctx, data.username); if (!user) { return false; // Instant return (~1-5ms) } const passwordMatch = await this.verifyUserPassword(ctx, user.id, data.password); // Password check takes ~200-400ms with bcrypt (12 rounds) ```
The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts.
### Impact - Attackers can enumerate valid user accounts - Enables targeted brute-force or phishing attacks - Information disclosure (account existence)
### Recommended Fix Perform a dummy bcrypt check when user is not found to ensure consistent response times.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vendurehq/vendure/security/advisories/GHSA-6f65-4fv2-wwch[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-25050[ADVISORY]
- https://github.com/vendurehq/vendure/commit/7f0c5556ecddb44a5d5208677a45fdd5923b0cc9[WEB]
- https://github.com/vendurehq/vendure[PACKAGE]
- https://github.com/vendurehq/vendure/releases/tag/v3.5.3[WEB]