PT-2026-96162 · Tinyauth · Tinyauth
CVE-2026-77561
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Tinyauth versions prior to 5.1.0
Description
An unauthenticated remote attacker can trigger a global login lockdown by sending POST requests to the '/api/user/login' endpoint using 257 distinct nonexistent usernames. This occurs because the
loginHandler function in internal/controller/user controller.go passes identifiers to the RecordLoginAttempt function in internal/service/auth service.go, which activates lockdownMode once the MaxLoginAttemptRecords map reaches its capacity. Consequently, the IsAccountLocked function checks this global state before validating accounts, resulting in valid users receiving HTTP 429 responses until the auth.loginTimeout expires, which is approximately 300 seconds by default. While the attack can be repeated, it does not invalidate existing authenticated sessions.Recommendations
Update Tinyauth to version 5.1.0.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tinyauth