CVE-2026-48166 | filamentphp filament up to 4.11.4/5.6.4 Registered Email timing discrepancy (GHSA-5w46-g9pq-wh6f / EUVD-2026-38393)
A vulnerability was found in filamentphp filament up to 4.11.4/5.6.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Registered Email Handler. Such manipulation leads to observable timing discrepancy.
This vulnerability is uniquely identified as CVE-2026-48166. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.