Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
Summary
| CVE | CVE-2026-77561 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-21 17:18:52 UTC |
| Updated | 2026-09-24 23:19:02 UTC |
| Description | Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a global login lockdown. internal/controller/user_controller.go loginHandler passes each attacker-controlled identifier to internal/service/auth_service.go RecordLoginAttempt, which invokes lockdownMode after the map reaches its cap. IsAccountLocked checks that global state before validating unrelated accounts, causing valid users to receive HTTP 429 until auth.loginTimeout expires, approximately 300 seconds by default. The attack can be repeated, but existing authenticated sessions are not invalidated. This issue is fixed in version 5.1.0. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.006000000 probability, percentile 0.465770000 (date 2026-09-27)
Problem Types: CWE-307 | CWE-307 CWE-307: Improper Restriction of Excessive Authentication Attempts
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Tinyauthapp | Tinyauth | affected < 5.1.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/tinyauthapp/tinyauth/pull/943 | [email protected] | github.com | |
| github.com/tinyauthapp/tinyauth/releases/tag/v5.1.0 | [email protected] | github.com | |
| github.com/tinyauthapp/tinyauth/pull/1008 | [email protected] | github.com | |
| github.com/tinyauthapp/tinyauth/commit/654b5cc436fc67865c1f55edf9ba9fbde... | [email protected] | github.com | |
| github.com/tinyauthapp/tinyauth/commit/dade1e2c8f27a23df56ac216dcaf4b370... | [email protected] | github.com | |
| github.com/tinyauthapp/tinyauth/security/advisories/GHSA-9xhm-w3wj-xhqh | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.