tinyauth records
3 published records for vendor tinyauth.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-33544No exploit | Tinyauth has OAuth account confusion via shared mutable state on singleton service instancestinyauth · tinyauth · CWE-362 | High7.7 | — | 0.3% | Apr 2, 2026 |
28Monitor | CVE-2026-32246No exploit | Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpointtinyauth · tinyauth · CWE-287 | High7.1 | — | 0.4% | Mar 12, 2026 |
26Monitor | CVE-2026-32245No exploit | Tinyauth's OIDC authorization codes are not bound to client on token exchangetinyauth · tinyauth · CWE-863 | Medium6.5 | — | 0.3% | Mar 12, 2026 |
- CVE-2026-3354430Monitor
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances
HighCVSS 7.7No exploitEPSS 0%tinyauth · tinyauthApr 2, 2026
- CVE-2026-3224628Monitor
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
HighCVSS 7.1No exploitEPSS 0%tinyauth · tinyauthMar 12, 2026
- CVE-2026-3224526Monitor
Tinyauth's OIDC authorization codes are not bound to client on token exchange
MediumCVSS 6.5No exploitEPSS 0%tinyauth · tinyauthMar 12, 2026