Back

MEDIUM

tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling

Published Jul 28, 2026

Description

tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length. Attackers can exploit the discrepancy between tiny_http's improper Transfer-Encoding parsing and a correctly-implemented front-end proxy to produce two distinct interpretations of a single byte stream, enabling request smuggling, and can additionally send non-chunked bodies with non-chunked Transfer-Encoding values to cause failed body reads that tie up connections and consume worker threads without signaling errors to clients.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 28, 2026
Updated Aug 14, 2026
Reserved Jul 27, 2026
CISA Vulnrichment
Updated Jul 28, 2026
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Jul 28, 2026
Updated Aug 14, 2026
Exploited since n/a
EUVD-2026-49881