📦 Tinyauth

by Tinyauth

🔍 What is Tinyauth?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-32246

HIGH CVSS 8.5 Mar 12, 2026

This vulnerability allows attackers who know a user's password but not their TOTP secret to bypass multi-factor authentication in Tinyauth. By exploiting the OIDC authorization endpoint, they can obta...

CVE-2026-32245

MEDIUM CVSS 6.5 Mar 12, 2026

This vulnerability allows malicious OIDC client operators to exchange authorization codes issued to other clients, obtaining access tokens for users who never authorized their applications. This affec...