{"id":"GO-2026-6564","summary":"Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth","details":"Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service in github.com/tinyauthapp/tinyauth","aliases":["CVE-2026-77561","GHSA-9xhm-w3wj-xhqh"],"modified":"2026-10-01T20:45:14.024702594Z","published":"2026-10-01T20:23:38Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6564"},"references":[{"type":"ADVISORY","url":"https://github.com/tinyauthapp/tinyauth/security/advisories/GHSA-9xhm-w3wj-xhqh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77561"},{"type":"FIX","url":"https://github.com/tinyauthapp/tinyauth/commit/654b5cc436fc67865c1f55edf9ba9fbded50b74f"},{"type":"FIX","url":"https://github.com/tinyauthapp/tinyauth/commit/dade1e2c8f27a23df56ac216dcaf4b37081698e7"},{"type":"FIX","url":"https://github.com/tinyauthapp/tinyauth/pull/1008"},{"type":"FIX","url":"https://github.com/tinyauthapp/tinyauth/pull/943"},{"type":"WEB","url":"https://github.com/tinyauthapp/tinyauth/releases/tag/v5.1.0"}],"affected":[{"package":{"name":"github.com/tinyauthapp/tinyauth","ecosystem":"Go","purl":"pkg:golang/github.com/tinyauthapp/tinyauth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.1-0.20260715123057-dade1e2c8f27"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6564.json"}}],"schema_version":"1.9.0"}