← Vulnerability feed

Vulnerability record · CVE-2022-40482 · published 25 April 2023

CVE-2022-40482: Laravel framework observable discrepancy vulnerability

Laravel · Framework

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

5.3 CVSS 3.1 Medium EPSS 0.89% · top 42.3% CWE-203 · Observable discrepancy
5.3CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43617Laravel framework unrestricted file upload vulnerabilityLaravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…EPSS 20%8.8CVE-2020-19316Laravel framework os command injection vulnerabilityOS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.EPSS 2.5%8.8CVE-2018-6330Laravel framework sql injection vulnerabilityLaravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.EPSS 1.6%8.7CVE-2024-52301Laravel framework argument injection alters request environmentLaravel mishandles the register_argc_argv PHP directive: when that directive is on, a crafted query string on any URL can inject argv values that cha…EPSS 45%analysed6.9CVE-2025-27515Laravel framework vulnerabilityLaravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious …EPSS 0.73%6.1CVE-2024-13919Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route para…EPSS 0.52%6.1CVE-2024-13918Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request pa…EPSS 0.59%6.1CVE-2021-43808Laravel framework cross-site scripting vulnerabilityLaravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerabi…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2022-40482), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.