Loading the catalog…
Loading the catalog…
github.com/tinyauthapp/tinyauth
high severity · CVSS 8.1 · CWE-178 · go github.com/tinyauthapp/tinyauth · affected < 1.0.1-0.20260720133915-80bc87188ec3 · fixed in 1.0.1-0.20260720133915-80bc87188ec3
What RADAR observed and classified to build this opportunity. It is what the source published, not a verification that the offer is still active.
CVE-2026-77560: Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for — github.com/tinyauthapp/tinyauth, fixed in 1.0.1-0.20260720133915-80bc87188ec3
Open sourceOpens an external website. Availability and terms may change.