Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy
The NativeAuthenticationStrategy.authenticate() method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses).