Skip to content

Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy

Low severity GitHub Reviewed Published Jan 30, 2026 in vendurehq/vendure • Updated Jan 30, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts