Intel

AIKIDO-2025-10537

github.com/hashicorp/cap is vulnerable to Observable Timing Discrepancy

Observable Timing Discrepancy Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 8, 2025

15

Low Risk

This Affects:

GOgithub.com/hashicorp/cap
0.1.0 - 0.9.0
Fixed in 0.9.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to timing attacks due to the use of a non-constant-time hash comparison in the verifyHashClaim function of the OIDC implementation. This flaw may allow attackers to infer valid hash values through response time analysis, potentially compromising the integrity of the verification process.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/cap is vulnerable to Observable Timing Discrepancy in versions 0.1.0 - 0.9.0.

How to fix this

Upgrade the github.com/hashicorp/cap library to the patch version.