PT-2026-96163 · Tinyauth · Tinyauth

CVE-2026-77582

·

Published

2026-09-21

·

Updated

2026-09-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tinyauth versions prior to 5.1.0
Description Tinyauth exposes a timing difference during authentication attempts that allows a remote observer to distinguish between existing and nonexistent local usernames. This occurs because the loginHandler function in internal/controller/user controller.go and the basicAuth function in internal/middleware/context middleware.go return responses quickly when the auth service.go reports a missing user, whereas existing users trigger bcrypt password verification, which takes more time. Repeated measurements of these response times can disclose valid usernames, facilitating targeted credential attacks.
Recommendations Update to version 5.1.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77582
GHSA-456H-WW26-F758

Affected Products

Tinyauth