CWE-204: Observable Response Discrepancy
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
175 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-33419 — MinIO: LDAP login brute-force via user enumeration and missing rate limit
- CVE-2025-5485 — SinoTrack GPS Receiver Weak Authentication
- CVE-2018-25350 — userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
- CVE-2026-6207 — Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows System Footprinting. T
- CVE-2026-60007 — In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
- CVE-2026-15747 — Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
- CVE-2025-46390 — CWE-204: Observable Response Discrepancy
- CVE-2025-3092 — MB connect line: Observable response discrepancy in mbCONNECT24/mymbCONNECT24
- CVE-2025-61907 — Icinga 2 API users could access restricted values in filter expressions
- CVE-2025-69243 — User enumeration in Raytha CMS
- CVE-2025-67874 — ChurchCRM has plaintext password return in response
- CVE-2025-62236 — Frontier Airlines publicly available email address validation
- CVE-2025-59116 — User enumeration in Windu CMS
- CVE-2025-54834 — OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration
- CVE-2025-40806 — A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerabl
- CVE-2025-30280 — A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions
- CVE-2025-2910 — User enumeration vulnerability in MeetMe products
- CVE-2025-24980 — Pimcore Admin Classic Bundle allows user enumeration
- CVE-2025-23214 — Cosmos userbase checking vulnerability
- CVE-2025-0693 — Issue with AWS Sign-in IAM User Login Flow - Possible Username Enumeration
Recently published
- CVE-2026-86758 — Snipe-IT before 8.7.0 License Key Exposure via CSV Export
- CVE-2026-19205 — User Enumeration in GastroMenum's GastroMenum Web Panel
- CVE-2026-19080 — Username Enumeration in Menulux Software's Menulux Portal
- CVE-2026-78584 — Observable Response Discrepancy in Kibana Leading to Cross-Space Information Disclosure
- CVE-2026-84307 — Filament: Password validity disclosure for accounts denied panel access on login page
- CVE-2026-81033 — Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy
- CVE-2026-75575 — Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
- CVE-2026-27462 — Combodo iTop: User enumeration via password reset
- CVE-2026-66002 — Frappe: User Enumeration via PDDR
- CVE-2026-54739 — Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential
- CVE-2026-19965 — automad Password Reset Endpoint UserController.php requestPasswordResetToken response discrepancy
- CVE-2026-14672 — PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle
- CVE-2026-73306 — Budibase: Account Enumeration via Login Lockout Response Differential
- CVE-2026-72588 — bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Recovery
- CVE-2026-55998 — Cluster Existence Oracle via Unauthenticated Import Endpoint
- CVE-2026-60007 — In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
- CVE-2026-14202 — Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital Human Resources
- CVE-2026-54768 — WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
- CVE-2026-42218 — XRDP is vulnerable to a server timing attack, leading to user enumeration
- CVE-2024-23574 — HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to