github.com/steveiliop56/tinyauth
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/steveiliop56/tinyauthpage 1 of 1
- CVE-2026-32245MEDIUMCVSS 6.5EG 6.5fixed in 1.0.1-20260311144920-9eb2d33064b72026-03-12
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator ca…
- CVE-2026-32246HIGHCVSS 7.1EG 7.1fixed in 1.0.1-20260311144920-9eb2d33064b72026-03-12
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who kno…
- CVE-2026-33544HIGHCVSS 7.7EG 7.7fixed in 1.0.1-0.20260401140714-fc1d4f2082a52026-04-02
Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct …
- CVE-2026-77561MEDIUMCVSS 5.3EG 5.3fixed in 1.0.1-0.20260715123057-dade1e2c8f272026-09-21
Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global …
Check whether github.com/steveiliop56/tinyauth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/steveiliop56/tinyauth CVEs against the assets you own.
Book a Demo →