—
GO-2026-5296
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
Details
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/steveiliop56/tinyauth
Introduced in:
0 Fixed in: 1.0.1-0.20260401140714-fc1d4f2082a5 Fix
go get github.com/steveiliop56/tinyauth@v1.0.1-0.20260401140714-fc1d4f2082a5 References
- https://github.com/steveiliop56/tinyauth/security/advisories/GHSA-9q5m-jfc4-wc92 [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-33544 [ADVISORY]
- https://github.com/steveiliop56/tinyauth/commit/f26c2171610d5c2dfbba2edb6ccd39490e349803 [FIX]
- https://github.com/steveiliop56/tinyauth/releases/tag/v5.0.5 [WEB]