Tinyweb
Ritlabs · 8 CVEs
CVE-2026-29046
CRITICAL
TinyWeb: HTTP Header Control Character Injection into CGI Environment
Mar 6, 2026
CVE-2026-28497
CRITICAL
TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling)
Mar 6, 2026
CVE-2026-27633
HIGH
TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)
Feb 25, 2026
CVE-2026-27630
HIGH
TinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris)
Feb 25, 2026
CVE-2026-27613
CRITICAL
CGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)
Feb 25, 2026
CVE-2026-22781
CRITICAL
TinyWeb CGI Command Injection
Jan 12, 2026
CVE-2024-5193
MEDIUM
Ritlabs TinyWeb Server Request crlf injection
May 22, 2024
CVE-2024-34199
HIGH
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when send…
May 10, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-29046 | TinyWeb: HTTP Header Control Character Injection into CGI Environment | CRITICAL | 0.58% | Mar 6, 2026 |
| CVE-2026-28497 | TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling) | CRITICAL | 0.69% | Mar 6, 2026 |
| CVE-2026-27633 | TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS) | HIGH | 0.82% | Feb 25, 2026 |
| CVE-2026-27630 | TinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris) | HIGH | 0.82% | Feb 25, 2026 |
| CVE-2026-27613 | CGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam) | CRITICAL | 1.37% | Feb 25, 2026 |
| CVE-2026-22781 | TinyWeb CGI Command Injection | CRITICAL | 2.47% | Jan 12, 2026 |
| CVE-2024-5193 | Ritlabs TinyWeb Server Request crlf injection | MEDIUM | 0.66% | May 22, 2024 |
| CVE-2024-34199 | TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the re… | HIGH | 1.23% | May 10, 2024 |
Showing 1 to 8 of 8 CVEs