CVE-2026-32245

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued to. A malicious OIDC client operator can exchange another client's authorization code using their own client credentials, obtaining tokens for users who never authorized their application. This violates RFC 6749 Section 4.1.3. This vulnerability is fixed in 5.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tinyauth:tinyauth:*:*:*:*:*:*:*:*

History

19 Mar 2026, 20:46

Type Values Removed Values Added
CPE cpe:2.3:a:tinyauth:tinyauth:*:*:*:*:*:*:*:*
First Time Tinyauth tinyauth
Tinyauth
Summary
  • (es) Tinyauth es un servidor de autenticación y autorización. Anterior a la 5.0.3, el endpoint de token OIDC no verifica que el cliente que intercambia un código de autorización sea el mismo cliente al que se le emitió el código. Un operador de cliente OIDC malicioso puede intercambiar el código de autorización de otro cliente usando sus propias credenciales de cliente, obteniendo tokens para usuarios que nunca autorizaron su aplicación. Esto viola la Sección 4.1.3 del RFC 6749. Esta vulnerabilidad se corrige en la 5.0.3.
References () https://github.com/steveiliop56/tinyauth/commit/b2a1bfb1f532e87f205fa3afa3fc9f148c53ab89 - () https://github.com/steveiliop56/tinyauth/commit/b2a1bfb1f532e87f205fa3afa3fc9f148c53ab89 - Patch
References () https://github.com/steveiliop56/tinyauth/releases/tag/v5.0.3 - () https://github.com/steveiliop56/tinyauth/releases/tag/v5.0.3 - Release Notes
References () https://github.com/steveiliop56/tinyauth/security/advisories/GHSA-xg2q-62g2-cvcm - () https://github.com/steveiliop56/tinyauth/security/advisories/GHSA-xg2q-62g2-cvcm - Exploit, Third Party Advisory

12 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 19:16

Updated : 2026-03-19 20:46


NVD link : CVE-2026-32245

Mitre link : CVE-2026-32245

CVE.ORG link : CVE-2026-32245


JSON object : View

Products Affected

tinyauth

  • tinyauth
CWE
CWE-863

Incorrect Authorization