Critical severity9.1NVD Advisory· Published Dec 27, 2022· Updated Jun 17, 2026
CVE-2020-36569
CVE-2020-36569
Description
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/nanobox-io/golang-nanoauthGo | >= 0.0.0-20160722212129-ac0cc4484ad4, < 0.0.0-20200131131040-063a3fb69896 | 0.0.0-20200131131040-063a3fb69896 |
Affected products
3- cpe:2.3:a:digitalocean:golang-nanoauth:*:*:*:*:*:go:*:*Range: >=2016-07-22,<=2020-01-31
- ghsa-coordsRange: >= 0.0.0-20160722212129-ac0cc4484ad4, < 0.0.0-20200131131040-063a3fb69896
- github.com/nanobox-io/golang-nanoauth/github.com/nanobox-io/golang-nanoauthv5Range: 0.0.0-20160722212129-ac0cc4484ad4
Patches
Vulnerability mechanics
References
5- github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-hrm3-3xm6-x33hghsaADVISORY
- github.com/nanobox-io/golang-nanoauth/pull/5nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-36569ghsaADVISORY
- pkg.go.dev/vuln/GO-2020-0004nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.