CVE-2026-77582: CWE-208: Observable Timing Discrepancy in tinyauthapp tinyauth
Tinyauth versions prior to 5.1.0 have a timing discrepancy vulnerability that allows remote attackers to distinguish between existing and nonexistent usernames during authentication attempts. This is due to faster response times when a username is missing compared to when bcrypt password verification occurs for existing users. The vulnerability enables attackers to enumerate valid usernames, facilitating targeted credential attacks. The issue is fixed in version 5.1.0.
AI Analysis
Technical Summary
Tinyauth, an authentication and authorization server, prior to version 5.1.0, leaks information about valid usernames through observable timing differences during login attempts. Specifically, the loginHandler and basicAuth functions return quickly if a user does not exist, while existing users trigger bcrypt password verification, which takes longer. This timing discrepancy can be measured remotely and used to enumerate valid usernames, potentially aiding attackers in credential-based attacks. The vulnerability is tracked as CVE-2026-77582 and classified under CWE-208 (Observable Timing Discrepancy).
Potential Impact
Attackers can remotely determine which usernames exist on the Tinyauth server by measuring response times during authentication attempts. This information disclosure facilitates targeted credential attacks such as brute force or password spraying against valid accounts. There is no indication of privilege escalation or direct code execution from this vulnerability alone.
Mitigation Recommendations
Upgrade Tinyauth to version 5.1.0 or later, where this timing discrepancy vulnerability has been fixed. No other mitigation is indicated or necessary once the fix is applied.
CVE-2026-77582: CWE-208: Observable Timing Discrepancy in tinyauthapp tinyauth
Description
Tinyauth versions prior to 5.1.0 have a timing discrepancy vulnerability that allows remote attackers to distinguish between existing and nonexistent usernames during authentication attempts. This is due to faster response times when a username is missing compared to when bcrypt password verification occurs for existing users. The vulnerability enables attackers to enumerate valid usernames, facilitating targeted credential attacks. The issue is fixed in version 5.1.0.
CVSS v4.0
Score 6.9medium
Affected software
tinyauthapp
tinyauth
pkg:github/tinyauthapp/tinyauthRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Tinyauth, an authentication and authorization server, prior to version 5.1.0, leaks information about valid usernames through observable timing differences during login attempts. Specifically, the loginHandler and basicAuth functions return quickly if a user does not exist, while existing users trigger bcrypt password verification, which takes longer. This timing discrepancy can be measured remotely and used to enumerate valid usernames, potentially aiding attackers in credential-based attacks. The vulnerability is tracked as CVE-2026-77582 and classified under CWE-208 (Observable Timing Discrepancy).
Potential Impact
Attackers can remotely determine which usernames exist on the Tinyauth server by measuring response times during authentication attempts. This information disclosure facilitates targeted credential attacks such as brute force or password spraying against valid accounts. There is no indication of privilege escalation or direct code execution from this vulnerability alone.
Mitigation Recommendations
Upgrade Tinyauth to version 5.1.0 or later, where this timing discrepancy vulnerability has been fixed. No other mitigation is indicated or necessary once the fix is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T20:35:30.148Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab1abbf55bf5e2cf58b46a3
Added to database: 09/21/2026, 22:12:15 UTC
Last enriched: 09/21/2026, 22:15:29 UTC
Last updated: 09/21/2026, 22:21:35 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.