Podatności / NVD · CVSS 6.9
CVE-2026-77582 · Tinyauth is an authentication and authorization server.
- Identyfikator
- CVE-2026-77582
- CVSS
- 6.9 MEDIUM
- CISA KEV
- nie ma w katalogu
- Opublikowano
- 2026-09-21
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth return quickly after internal/service/auth_service.go reports a missing user, while an existing user causes bcrypt password verification work. Repeated measurements can therefore disclose valid usernames and support targeted credential attacks. This issue is fixed in version 5.1.0.