CVE-2026-77582
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth return quickly after internal/service/auth_service.go reports a missing user, while an existing user causes bcrypt password verification work. Repeated measurements can therefore disclose valid usernames and support targeted credential attacks. This issue is fixed in version 5.1.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tinyauthapp | tinyauth | < 5.1.0 | affected |
Weaknesses
- CWE-208: CWE-208: Observable Timing Discrepancy
References
- https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-456h-ww26-f758
- https://github.com/tinyauthapp/tinyauth/pull/1004
- https://github.com/tinyauthapp/tinyauth/commit/c22925c2fba981875d0a2b09dd3ee41c0ae4c310
- https://github.com/tinyauthapp/tinyauth/releases/tag/v5.1.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.