PatchSiren

tinyauth CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM tinyauth CVE published 2026-09-25

CVE-2026-97736

CVE-2026-97736 is a medium-severity vulnerability in tinyauth before version 5.1.3. The issue allows for rule bypass by appending an allowed route string due to an unanchored regular expression. This CVE was published on 2026-09-25T04:17:50.977Z and was last modified on 2026-09-26T23:16:43.433Z. Defenders and security teams responsible for tinyauth installations should assess exposure to this vulnerabilit [truncated]