PT-2026-96161 · Tinyauth · Tinyauth

CVE-2026-77560

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tinyauth versions prior to 5.1.2
Description Tinyauth performs case-sensitive comparisons of forwarded hostnames, whereas reverse proxies typically route equivalent hostnames case-insensitively. This discrepancy allows an authenticated user with low privileges to bypass per-app access controls by using a hostname with different casing. Specifically, the lookupStaticACLs() and GetAccessControls() functions in internal/service/access controls service.go, as well as the GetLabels() function in internal/service/docker service.go, may fail to identify the configured application and return an empty access-control object. Consequently, the proxyHandler() in internal/controller/proxy controller.go treats empty restrictions for users, groups, OAuth, LDAP, and IP as permissive, granting access to an application that should have excluded the user. Unauthenticated users are still required to log in, and global login-time allowlists remain effective.
Recommendations Update to version 5.1.2.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77560
GHSA-328G-JX67-V94G

Affected Products

Tinyauth