The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
- http://www.vanillaforums.org/discussion/comment/134729/#Comment_134729
No PoCs found on GitHub currently.