CVE-2026-97736
5.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Summary
tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tinyauth | tinyauth | 0 < 5.1.3 | affected |
Weaknesses
- CWE-777: CWE-777 Regular Expression without Anchors
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.