CVE-2026-32245 — Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued — CVE Database · The Intelligence Room