Vulnerability GO-2026-6564
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth
v0.1.0-beta.1 - v1.0.0
v0.1.0-beta.1 - v1.0.0
Summary
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth
Details
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 hours ago
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth
v0.1.0-beta.1 - v1.0.0 GO-2026-6552
v0.1.0-beta.1 - v1.0.0 GO-2026-6552
Unknown
6 hours ago
Tinyauth: User enumeration attack by timing oracle in github.com/tinyauthapp/tinyauth
v0.1.0-beta.1 - v1.0.0 GO-2026-6555
v0.1.0-beta.1 - v1.0.0 GO-2026-6555
High Risk
9 days ago
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
v0.1.0-beta.1 - v1.0.0 GHSA-328g-jx67-v94g
v0.1.0-beta.1 - v1.0.0 GHSA-328g-jx67-v94g
Medium Risk
9 days ago
Tinyauth: User enumeration attack by timing oracle
v0.1.0-beta.1 - v1.0.0 GHSA-456h-ww26-f758
v0.1.0-beta.1 - v1.0.0 GHSA-456h-ww26-f758
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC