CVE-2026-97736
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 25, 2026
Vendor
unknown
Description
tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.
tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.