CVE-2026-77582Medium· 6.9▾ SunlitTinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_controller.go loginHandler and internal/middleware/context_middleware.go basicAuth return quickly after internal/service/auth_service.go reports a missing user, while an existing user causes bcrypt password verification work. Repeated measurements can therefore disclose valid usernames and support targeted credential attacks. This issue is fixed in version 5.1.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77561Medium· 5.3Tinyauth is an authentication and authorization server
CVE-2026-77560High· 8.1Tinyauth is an authentication and authorization server
CVE-2026-47783High· 8.1In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVE-2026-70658High· 7.4Pay is a payments engine for Ruby on Rails 6.0 and higher
CVE-2023-24035Low· 3.5An issue was discovered in Nagios XI before 5.9.3
CVE-2024-39329Medium· 5.3An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14