CVE Browser
CVE-2026-66753 MEDIUM
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
CVSS 6.3 EPSS 0.30% Jul 28, 2026
CVE-2026-66752 MEDIUM
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
CVSS 6.3 EPSS 0.33% Jul 28, 2026
CVE-2020-35884 MEDIUM
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
CVSS 6.5 EPSS 1.09% Dec 31, 2020
CVE-2017-16097 HIGH
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the…
CVSS 7.5 EPSS 2.00% Jun 7, 2018
npm
Showing 1 to 4 CVEs · page 1