CVE-2020-36569: Digitalocean Golang-Nanoauth

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.

Affected products

  • Digitalocean Golang-Nanoauth: from 2016-07-22, up to and including 2020-01-31

Published 2022-12-27. Last modified 2026-06-17.