Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames
A Timing-based username enumeration in Basic Authentication vulnerability due to early response on invalid usernames could allow attackers to identify valid users and focus their efforts on targeted brute-force or credential-stuffing attacks.