tinyauth 产品相关 6 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。
厂商: steveiliop56
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-77561 | Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service CWE-307 | 5.3 | Medium | 2026-09-21 |
| CVE-2026-77582 | Tinyauth: User enumeration attack by timing oracle CWE-208 | 6.9 | Medium | 2026-09-21 |
| CVE-2026-77560 | Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for CWE-178 | 8.1 | High | 2026-09-21 |
| CVE-2026-33544 | Tinyauth 竞争条件问题漏洞 CWE-362 | 7.7 | High | 2026-04-02 |
| CVE-2026-32246 | Tinyauth 授权问题漏洞 CWE-287 | 8.5 | High | 2026-03-12 |
| CVE-2026-32245 | Tinyauth 安全漏洞 CWE-863 | 6.5 | Medium | 2026-03-12 |
tinyauth 产品累计公开 6 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。