Executive brief
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth
Affected products
- Go github.com/steveiliop56/tinyauth
Junglewise Threat Intelligence
CVE-2026-33544 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/steveiliop56/tinyauth (Go). Vendors: Go.
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances in github.com/steveiliop56/tinyauth