
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23892 is a timing side-channel vulnerability in OctoPrint's API key authentication mechanism, classified as "Timing Side-Channel in API Key Authentication." It affects OctoPrint versions up to and including 1.11.5 (pip package), and was disclosed on January 27, 2026, by researcher Knox Liu (credited as yueyueL) via responsible disclosure. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 6.0 (Medium) (Github Advisory, OctoPrint Release).
The root cause is classified as CWE-208 (Observable Timing Discrepancy). OctoPrint's API key validation used standard Python string equality (==) for comparing submitted API keys against stored values, which short-circuits on the first mismatched character — causing measurably different response times depending on how many leading characters match. An attacker with network access to the OctoPrint instance could exploit this by sending repeated API key guesses and statistically analyzing response latencies to recover the key one character at a time. The fix, committed in OctoPrint commit 249fd80, replaces all three vulnerable comparison sites (users.py, appkeys/__init__.py, and server/util/__init__.py) with Python's hmac.compare_digest(), which runs in constant time regardless of where a mismatch occurs (Github Advisory).
Successful exploitation would allow an attacker to extract a valid API key from an OctoPrint instance, granting unauthorized access to the web interface used to control consumer 3D printers. This could enable an attacker to manipulate print jobs, alter printer settings, or potentially cause physical damage to hardware. There is no integrity or availability impact at the system level from the vulnerability itself; the primary risk is confidentiality loss of the API credential. The practical risk is constrained by network conditions — high latency or noise significantly reduces the feasibility of the attack (Github Advisory).
No public proof-of-concept exploit exists, and no in-the-wild exploitation has been observed as of the disclosure date. The OctoPrint maintainers explicitly noted that an actual PoC was not achieved during the vulnerability research process. The EPSS score is approximately 0.006% (very low probability of exploitation within 30 days), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires adjacent network access, high attack complexity, and specific environmental conditions (low-latency, low-noise network) (Github Advisory, Feedly).
X-Api-Key header or equivalent authentication parameter; requests resulting in 403/401 responses in rapid succession.server/util/__init__.py) from an unexpected source.The vulnerability is patched in OctoPrint version 1.11.6, released January 27, 2026. Administrators should upgrade immediately via pip install octoprint --upgrade or through the OctoPrint update mechanism. As a network-level workaround, administrators should ensure OctoPrint is not exposed on hostile or public networks — placing it behind a firewall or VPN significantly reduces the attack surface, as the exploit requires adjacent network access with low latency and noise (OctoPrint Release, Github Advisory).
The OctoPrint maintainer (foosel) published a detailed security advisory and release notes acknowledging the responsible disclosure by researcher Knox Liu (yueyueL) and emphasizing the theoretical nature of the attack. The advisory explicitly noted that no working PoC was produced and that real-world exploitability is highly dependent on network conditions, framing this as a precautionary fix rather than an urgent critical patch (OctoPrint Release, Github Advisory).
hmac.compare_digestSource: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."