Critical Collision Bug in Auth Library Merges All Patreon Users
ID: ea18471c-46d5-5d11-a38a-213840865e15
STIX ID: report--ea18471c-46d5-5d11-a38a-213840865e15
Feed Name: securityonline.info
Threat Score
A critical OAuth identity-collision vulnerability (CVE-2026-42560, CVSS 9.1) in a Go auth library causes all Patreon-authenticated users to be assigned the same local user ID, enabling impersonation, subscription/attribute leakage, data corruption, and potential privilege escalation; affected versions include Auth v1 >=1.18.0 through <=1.25.1 and Auth v2 >=2.0.0 through <=2.1.1 — upgrade to authv2 2.1.2+ and provide migration guidance for merged accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
