VDB
Sign up
LOW3.7

PYSEC-2026-2008

vantage6 vulnerable to username timing attack

Quick fix

PYSEC-2026-2008 — vantage6-server: upgrade to the fixed version with the command below.

pip install --upgrade 'vantage6-server>=4.2.0'

Details

### Impact It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks

### Workarounds No

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/vantage6-server
Introduced in: 0Fixed in: 4.2.0
Fixpip install --upgrade 'vantage6-server>=4.2.0'

References