CVE-2026-32702

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. From 2.7.0 to 2.8.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. It appears that the hashing function, which is the most time-consuming part of the process by design, occurs as part of the VerifyPassword function. With the short circuits occurring before the hashing function, a timing differential is introduced that exposes validity to the actor. This vulnerability is fixed in 2.8.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cleanuparr_project:cleanuparr:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:36

Type Values Removed Values Added
Summary
  • (es) Cleanuparr es una herramienta para automatizar la limpieza de archivos no deseados o bloqueados en Sonarr, Radarr y clientes de descarga compatibles como qBittorrent. Desde la versión 2.7.0 hasta la 2.8.0, el endpoint /api/auth/login contiene un fallo lógico que permite a atacantes remotos no autenticados enumerar nombres de usuario válidos midiendo el tiempo de respuesta de la aplicación. Parece que la función de hash, que es la parte del proceso que más tiempo consume por diseño, ocurre como parte de la función VerifyPassword. Con los cortocircuitos ocurriendo antes de la función de hash, se introduce una diferencia de tiempo que expone la validez al actor. Esta vulnerabilidad está corregida en la versión 2.8.1.

18 Mar 2026, 18:19

Type Values Removed Values Added
CPE cpe:2.3:a:cleanuparr_project:cleanuparr:*:*:*:*:*:*:*:*
First Time Cleanuparr Project
Cleanuparr Project cleanuparr
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-gjmf-m27r-2c9v - () https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-gjmf-m27r-2c9v - Exploit, Mitigation, Vendor Advisory

16 Mar 2026, 18:16

Type Values Removed Values Added
References () https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-gjmf-m27r-2c9v - () https://github.com/Cleanuparr/Cleanuparr/security/advisories/GHSA-gjmf-m27r-2c9v -

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32702

Mitre link : CVE-2026-32702

CVE.ORG link : CVE-2026-32702


JSON object : View

Products Affected

cleanuparr_project

  • cleanuparr
CWE
CWE-208

Observable Timing Discrepancy