Tinyauth

Tinyauth

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 25.09.2026 03:58:59
  • Zuletzt bearbeitet 30.09.2026 17:32:07

tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

  • EPSS 0.48%
  • Veröffentlicht 21.09.2026 16:48:21
  • Zuletzt bearbeitet 24.09.2026 23:19:02

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockd...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 02.04.2026 15:00:38
  • Zuletzt bearbeitet 07.04.2026 12:44:36

Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on s...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 12.03.2026 19:16:19
  • Zuletzt bearbeitet 19.03.2026 20:46:39

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator can exchange ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 12.03.2026 19:16:19
  • Zuletzt bearbeitet 19.03.2026 20:35:26

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's...