Tinyauth is a narrowly scoped authentication utility whose disclosures center on the Tinyauth product itself and cluster around race conditions, improper authentication logic, and authorization weaknesses that reflect the synchronization and access-control demands of credential-handling code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinyauth over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33544HIGH Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService | Apr 2, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-32246HIGH Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet co | Mar 12, 2026 | 7.1 | 25 | NO | NO |
CVE-2026-32245MEDIUM Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client | Mar 12, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinyauth.
Media articles that mention a CVE ID that affects a product developed by Tinyauth — matched by CVE ID, not by vendor name.