CVE-2025-70949Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-09: 1Mentions · 2026-03-16: 1Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 1Technical Details · 2026-04-27: 103-0603-0903-1604-27
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • أحمد رضا 🇵🇸@HunterXReda
    Disclosure

    الحمدلله At the very end of 2025, I discovered and reported multiple CVEs. Two high-severity ones found in the couch-auth NPM package are now officially published. CVE-2025-70948 https://www.cve.org/CVERecord?id=CVE-2025-70948 CVE-2025-70949 https://www.cve.org/CVERecord?id=CVE-2025-70949 Stay tuned for what's next

    Post summary

    The author reports the discovery and official publication of two high‑severity CVEs in the couch‑auth NPM package, providing links to their CVE records.

    20060264
    289 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    🚨 HIGH SEVERITY: CVE-2025-70949 (CVSS 7.5) Timing side-channel vulnerability in @perfood/couch-auth v0[.]26[.]0 allows unauthorized access to sensitive data. Patch immediately if using this package. #CVE #Vulnerability #PatchNow #ThreatIntel #CyberSecurity https://t.co/hEgY8q13Fz

    Post summary

    The tweet announces a new timing side-channel flaw (CVE‑2025‑70949) in @perfood/couch‑auth v0.26.0, highlights its severity, and urges users to apply the patch immediately.

    00000526
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70949 An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel. https://www.cve.org/CVERecord?id=CVE-2025-70949

    Post summary

    The text announces CVE-2025-70949, detailing a timing side‑channel flaw in @perfood/couch-auth v0.26.0 that could expose sensitive information.

    00000215
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70949 Timing Side-Channel Information Disclosure in @perfood/couch-auth v0.26.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70949

    Post summary

    A timing side‑channel information‑disclosure vulnerability (CVE-2025-70949) has been disclosed for perfood/couch‑auth v0.26.0; no PoC, exploit, or patch details are provided.

    0000083
    4.0K followersView on X

Explore more