PT-2026-96162 · Tinyauth · Tinyauth

CVE-2026-77561

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Tinyauth versions prior to 5.1.0
Description An unauthenticated remote attacker can trigger a global login lockdown by sending POST requests to the '/api/user/login' endpoint using 257 distinct nonexistent usernames. This occurs because the loginHandler function in internal/controller/user controller.go passes identifiers to the RecordLoginAttempt function in internal/service/auth service.go, which activates lockdownMode once the MaxLoginAttemptRecords map reaches its capacity. Consequently, the IsAccountLocked function checks this global state before validating accounts, resulting in valid users receiving HTTP 429 responses until the auth.loginTimeout expires, which is approximately 300 seconds by default. While the attack can be repeated, it does not invalidate existing authenticated sessions.
Recommendations Update Tinyauth to version 5.1.0.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77561
GHSA-9XHM-W3WJ-XHQH

Affected Products

Tinyauth