<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Timing Oracle — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/timing-oracle/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 27 Mar 2026 09:16:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/timing-oracle/feed.xml" rel="self" type="application/rss+xml"/><item><title>Doveadm Credentials Vulnerable to Timing Oracle Attack (CVE-2026-27856)</title><link>https://feed.craftedsignal.io/briefs/2026-03-doveadm-timing-oracle/</link><pubDate>Fri, 27 Mar 2026 09:16:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-doveadm-timing-oracle/</guid><description>Doveadm credentials are verified using direct comparison, making it susceptible to timing oracle attacks, allowing attackers to determine credentials and gain full access.</description><content:encoded>&lt;p>CVE-2026-27856 describes a vulnerability in Doveadm, a component often used in conjunction with mail servers such as Dovecot. The vulnerability stems from the direct comparison method used to verify credentials, making it susceptible to timing oracle attacks. This vulnerability was published on March 27, 2026. An attacker leveraging this flaw can potentially determine the configured credentials by observing the time it takes for the system to respond to different credential attempts. While no…&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>timing oracle</category><category>credential access</category><category>doveadm</category></item></channel></rss>