Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for in github.com/tinyauthapp/tinyauth
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6552"
}