Cosmos Home Server User Existence Verification Vulnerability

Vulnerability

A vulnerability in Cosmos Home Server versions prior to 0.17.7 allows for user existence verification through error code analysis during the login process. This issue arises because the application does not properly obscure whether a username is registered in the database, creating a potential vector for user enumeration. Although the vulnerability's impact is considered low due to rate limiting that hinders scanning attempts, it still poses a risk by allowing targeted checks for user accounts, except for the 'admin' username, which is explicitly blocked.

Impact

Exploitation of this vulnerability could lead to unauthorized user enumeration, allowing an attacker to determine which usernames are registered in the application.

Remediation

Users can upgrade to Cosmos Home Server version 0.17.7 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.9
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.