Advisories for Golang/Github.com/Steveiliop56/Tinyauth package

2026

Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service

Tinyauth's login rate-limit bookkeeping can enter a global lockdown mode when its in-memory login-attempt map reaches 256 distinct identifiers. Because unauthenticated POST /api/user/login requests for unknown usernames are recorded in this same map, a remote unauthenticated attacker can submit 257 unique bogus usernames and cause valid credentials for unrelated users to be treated as locked until auth.loginTimeout expires. This was confirmed against the stable v5.0.7 release. With default configuration, auth.loginTimeout …

Tinyauth has OAuth account confusion via shared mutable state on singleton service instances

All three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent requests. When two users initiate OAuth login for the same provider concurrently, a race condition between VerifyCode() and Userinfo() causes one user to receive a session with the other user's identity.