blob: c9face58cff89fac533b4cdacb1b8b60d9caa4a9 [file] [edit]
id: GO-2026-6552
modules:
- module: github.com/tinyauthapp/tinyauth
versions:
- fixed: 1.0.1-0.20260720133915-80bc87188ec3
vulnerable_at: 1.0.0
summary: |-
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the
(case-insensitive) hostname, letting an authenticated user reach apps they are
not on the allowlist for in github.com/tinyauthapp/tinyauth
cves:
- CVE-2026-77560
ghsas:
- GHSA-328g-jx67-v94g
references:
- advisory: https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-328g-jx67-v94g
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77560
- fix: https://github.com/tinyauthapp/tinyauth/commit/80bc87188ec3aabc5104c249eaa7b997973b9275
- fix: https://github.com/tinyauthapp/tinyauth/commit/e75605b2c534ec83525a33603e16d76baca13399
- fix: https://github.com/tinyauthapp/tinyauth/pull/1000
- fix: https://github.com/tinyauthapp/tinyauth/pull/1028
- web: https://github.com/tinyauthapp/tinyauth/releases/tag/v5.1.2
source:
id: GHSA-328g-jx67-v94g
created: 2026-09-28T14:11:14.500645-04:00
review_status: UNREVIEWED