CVE Explorer
CVE-2026-42560
auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the same local user.ID, instead of deriving a unique ID from the Patreon account returned by Patreon. In practice, this means all Patreon-authenticated users of an application using this library are collapsed into a single local identity. Any application that trusts token.User.ID as the stable account ke
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"auth","vendor":"go-pkgz","versions":[{"status":"affected","version":">= 1.18.0, < 1.25.2"},{"status":"affected","version":">= 2.0.0, < 2.1.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/go-pkgz/auth/commit/c0b15ee72a8401da83c01781c16636c521f42698","tags":["x_refsource_MISC"],"url":"https://github.com/go-pkgz/auth/commit/c0b15ee72a8401da83c01781c16636c521f42698"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/references/1
{"name":"https://github.com/go-pkgz/auth/releases/tag/v1.25.2","tags":["x_refsource_MISC"],"url":"https://github.com/go-pkgz/auth/releases/tag/v1.25.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/references/2
{"name":"https://github.com/go-pkgz/auth/releases/tag/v2.1.2","tags":["x_refsource_MISC"],"url":"https://github.com/go-pkgz/auth/releases/tag/v2.1.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/references/3
{"tags":["exploit"],"url":"https://github.com/go-pkgz/auth/security/advisories/GHSA-f6qq-3m3h-4g42"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/adp/0/references/0
{"name":"https://github.com/go-pkgz/auth/security/advisories/GHSA-f6qq-3m3h-4g42","tags":["x_refsource_CONFIRM"],"url":"https://github.com/go-pkgz/auth/security/advisories/GHSA-f6qq-3m3h-4g42"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:11e924590da7e92eff4d76943191a67896e10b9505d317d2452874f02ff2765d · sha256:f0adc9943d6321e7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.