Steveiliop56 Tinyauth vulnerabilities
3 known vulnerabilities affecting steveiliop56/tinyauth.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-33544P3HIGHCVSS 7.7fixed in 5.0.52026-04-02
CVE-2026-33544 [HIGH] CWE-362 CVE-2026-33544: Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth serv
Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent requests. When two users initiate OAuth login for the s
nvd
CVE-2026-32246P3HIGHCVSS 7.1fixed in 5.0.32026-03-12
CVE-2026-32246 [HIGH] CWE-287 CVE-2026-32246: Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpo
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtain valid OIDC tokens, completely bypassing the second facto
nvd
CVE-2026-32245P3MEDIUMCVSS 6.5fixed in 5.0.32026-03-12
CVE-2026-32245 [MEDIUM] CWE-863 CVE-2026-32245: Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator can exchange another client's authorization code using their own client credentials, obtaining tokens for users wh
nvd