blob: 5179ba1b94b37223bc7062d33c5e08f3755389e7 [file] [edit]
id: GO-2026-4688
modules:
- module: github.com/steveiliop56/tinyauth
non_go_versions:
- fixed: 1.0.1-20260311144920-9eb2d33064b7
vulnerable_at: 1.0.0
summary: Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint in github.com/steveiliop56/tinyauth
cves:
- CVE-2026-32246
ghsas:
- GHSA-3q28-qjrv-qr39
references:
- advisory: https://github.com/steveiliop56/tinyauth/security/advisories/GHSA-3q28-qjrv-qr39
- web: https://github.com/steveiliop56/tinyauth/releases/tag/v5.0.3
source:
id: GHSA-3q28-qjrv-qr39
created: 2026-03-12T19:41:08.020670455Z
review_status: UNREVIEWED