7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/steveiliop56/tinyauth is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-77561
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
HIGH 7.7
CVE-2026-33544
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances
UNKNOWN
CVE-2026-33544
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
MEDIUM 6.5
CVE-2026-32245
Tinyauth's OIDC authorization codes are not bound to client on token exchange
HIGH 8.5
CVE-2026-32246
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
UNKNOWN
CVE-2026-32245
Tinyauth's OIDC authorization codes are not bound to client on token exchange in github.com/steveiliop56/tinyauth
UNKNOWN
CVE-2026-32246
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint in github.com/steveiliop56/tinyauth
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes