CVE-2026-77582
— UNSCOREDpublic exploit availablePublished 2026-09-21 · Updated 2026-09-23
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth return quickly after internal/service/auth_service.go reports a missing user, while an existing user causes bcrypt password verification work. Repeated measurements can therefore disclose valid usernames and support targeted credential attacks. This issue is fixed in version 5.1.0.
Weaknesses
CWE-208
Public exploit & PoC references
- https://github.com/tinyauthapp/tinyauth/commit/c22925c2fba981875d0a2b09dd3ee41c0ae4c310
- https://github.com/tinyauthapp/tinyauth/pull/1004
- https://github.com/tinyauthapp/tinyauth/releases/tag/v5.1.0
- https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-456h-ww26-f758
- https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-456h-ww26-f758
All references
- https://github.com/tinyauthapp/tinyauth/commit/c22925c2fba981875d0a2b09dd3ee41c0ae4c310
- https://github.com/tinyauthapp/tinyauth/pull/1004
- https://github.com/tinyauthapp/tinyauth/releases/tag/v5.1.0
- https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-456h-ww26-f758
- https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-456h-ww26-f758
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- LOWCVE-2026-54872PoC
- LOWCVE-2026-54875PoC
- MEDIUMCVE-2026-58272PoC
- UNSCOREDCVE-2026-63132PoC
- LOWCVE-2026-77696PoC
- UNSCOREDCVE-2026-77987PoC
- MEDIUMCVE-2026-85725PoC
- UNSCOREDCVE-2026-88010PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.