VYPR
Vendor

Tinyauth

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2026-32246HigMar 12, 2026
    risk 0.48cvss 8.5epss 0.00

    Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP…

  • CVE-2026-77560HigSep 21, 2026
    risk 0.46cvss 8.1epss 0.01

    Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with…

  • CVE-2026-33544HigApr 2, 2026
    risk 0.43cvss 7.7epss 0.00

    Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared…

  • CVE-2026-77582MedSep 21, 2026
    risk 0.38cvss —epss 0.00

    Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and…

  • CVE-2026-32245MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator can exchange another client's…

  • CVE-2026-97736MedSep 25, 2026
    risk 0.28cvss 5.4epss 0.00

    tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

  • CVE-2026-77561MedSep 21, 2026
    risk 0.27cvss 5.3epss 0.01

    Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockdown.…