github.com/tinyauthapp/tinyauth
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/tinyauthapp/tinyauthpage 1 of 1
- CVE-2026-77560HIGHCVSS 8.1EG 8.1✓ Fixed in 1.0.1-0.20260720133915-80bc87188ec32026-09-21
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege use…
- CVE-2026-77582MEDIUMCVSS 6.9EG 6.9✓ Fixed in 1.0.1-0.20260714134959-c22925c2fba92026-09-21
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_control…
Check whether github.com/tinyauthapp/tinyauth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/tinyauthapp/tinyauth CVEs against the assets you own.
Book a Demo →