Vulnerability GO-2026-5296
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 06:43 PM UTC
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
v0.1.0-beta.1 - v1.0.0
v0.1.0-beta.1 - v1.0.0
Summary
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
Details
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 days ago
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
v0.1.0-beta.1 - v1.0.0 GHSA-9xhm-w3wj-xhqh
v0.1.0-beta.1 - v1.0.0 GHSA-9xhm-w3wj-xhqh
High Risk
6 months ago
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances
v0.1.0-beta.1 - v1.0.0 GHSA-9q5m-jfc4-wc92
v0.1.0-beta.1 - v1.0.0 GHSA-9q5m-jfc4-wc92
Unknown
6 months ago
Tinyauth's OIDC authorization codes are not bound to client on token exchange in github.com/steveiliop56/tinyauth
v0.1.0-beta.1 - v1.0.0 GO-2026-4689
v0.1.0-beta.1 - v1.0.0 GO-2026-4689
Unknown
6 months ago
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint in github.com/steveiliop56/tinyauth
v0.1.0-beta.1 - v1.0.0 GO-2026-4688
v0.1.0-beta.1 - v1.0.0 GO-2026-4688
High Risk
6 months ago
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
v0.1.0-beta.1 - v1.0.0 GHSA-3q28-qjrv-qr39
v0.1.0-beta.1 - v1.0.0 GHSA-3q28-qjrv-qr39
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 06:43 PM UTC
Last Modified
3 months ago
June 25, 2026 at 07:45 PM UTC