Skip to content
Noroxi

tinyauth records

3 published records for vendor tinyauth.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

3 records
  • Tinyauth has OAuth account confusion via shared mutable state on singleton service instances

    HighCVSS 7.7No exploitEPSS 0%

    tinyauth · tinyauthApr 2, 2026

  • Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint

    HighCVSS 7.1No exploitEPSS 0%

    tinyauth · tinyauthMar 12, 2026

  • Tinyauth's OIDC authorization codes are not bound to client on token exchange

    MediumCVSS 6.5No exploitEPSS 0%

    tinyauth · tinyauthMar 12, 2026