tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
Published Jul 28, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.33%
Description
tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length. Attackers can exploit the discrepancy between tiny_http's improper Transfer-Encoding parsing and a correctly-implemented front-end proxy to produce two distinct interpretations of a single byte stream, enabling request smuggling, and can additionally send non-chunked bodies with non-chunked Transfer-Encoding values to cause failed body reads that tie up connections and consume worker threads without signaling errors to clients.
Affected products
-
- Version 0StatusaffectedConstraints<=0.12.0
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-49881 Advisory
- https://github.com/theopaid/HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master exploittechnical-description
- https://www.vulncheck.com/advisories/tiny-http-http-request-smuggling-via-transfer-encoding-handling third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-49881 | Advisory | |
| https://github.com/theopaid/HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master | exploittechnical-description | |
| https://www.vulncheck.com/advisories/tiny-http-http-request-smuggling-via-transfer-encoding-handling | third-party-advisory |
Change history (0)
No recorded changes yet.