logo

Critical Collision Bug in Auth Library Merges All Patreon Users

ID: ea18471c-46d5-5d11-a38a-213840865e15

STIX ID: report--ea18471c-46d5-5d11-a38a-213840865e15

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

A critical OAuth identity-collision vulnerability (CVE-2026-42560, CVSS 9.1) in a Go auth library causes all Patreon-authenticated users to be assigned the same local user ID, enabling impersonation, subscription/attribute leakage, data corruption, and potential privilege escalation; affected versions include Auth v1 >=1.18.0 through <=1.25.1 and Auth v2 >=2.0.0 through <=2.1.1 — upgrade to authv2 2.1.2+ and provide migration guidance for merged accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.