GSSA-2026-04-P1V3KVGITLAB-GSSA-2026-04-P1V3KVApril 25, 20265.9 Medium
Non-constant-time CSRF token comparison and lax hex parsing in cobc-events
The CSRF middleware in cobc-events <1.0.1 compared the cookie nonce with `!==` before the timing-safe HMAC check and accepted malformed hex input, leaking timing data and weakening token verification.
Affected (1)
- gelhaus-solutionscobc-events
- ≥ 0.0.0Fixed in 1.0.1
Mitigations
Workarounds
- None — the CSRF mechanism cannot be safely disabled in production. Apply the upgrade.
Solutions
- Upgrade cobc-events to 1.0.1 or later.
Overview
The CSRF middleware in cobc-events <1.0.1 compared the cookie nonce with !== before the timing-safe HMAC check and accepted malformed hex input, leaking timing data and weakening token verification.
Severity
CVSS v3
5.9 Medium
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- Required
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- High
- Availability
- None
Weaknesses (3)
References (3)
- Patch in src/middleware/csrf.js (Patch)
- CWE-208: Observable Timing Discrepancy (Third-party advisory)
- CWE-352: Cross-Site Request Forgery (Third-party advisory)
Credits (5)
- Enno GelhausFinder · egelhaus@ennogelhaus.de
- Enno GelhausAnalyst · egelhaus@ennogelhaus.de
- Enno GelhausRemediation developer · egelhaus@ennogelhaus.de
- Enno GelhausRemediation reviewer · egelhaus@ennogelhaus.de
- Claude (Anthropic) — automated audit assistantTool · https://claude.com
Context
Impacts
Side-channel weakening of CSRF protection
CAPEC-189Defence-in-depth bypass via malformed hex tokens
Timeline
- 04/25/2026 00:00
Internal security audit started
- 04/25/2026 06:00
Vulnerability identified during audit
- 04/25/2026 12:00
Patch developed and merged to main
- 04/25/2026 14:00
cobc-events 1.0.1 released
- 04/25/2026 15:00
Advisory published