Tinyproxy / Tinyproxy
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-54388 | Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers | CRITICAL | 9.3 | Jun 17, 2026 |
| CVE-2026-54387 | Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization | CRITICAL | 9.3 | Jun 17, 2026 |
| CVE-2026-55202 | Tinyproxy - Stathost Detection Bypass via Host Header Manipulation | HIGH | 8.8 | Jun 17, 2026 |
| CVE-2026-31842 | Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling | HIGH | 8.7 | Apr 7, 2026 |
| CVE-2026-3945 | tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service | HIGH | 8.7 | Mar 30, 2026 |
| CVE-2025-63938 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c. | MEDIUM | 6.5 | Nov 26, 2025 |
| CVE-2023-49606 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trig… | CRITICAL | 9.8 | May 1, 2024 |
| CVE-2022-40468 | Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier u… | HIGH | 7.5 | Sep 19, 2022 |
| CVE-2017-11747 | main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local user… | MEDIUM | 5.5 | Jul 30, 2017 |
| CVE-2002-0847 | tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free). | HIGH | 7.5 | Apr 2, 2003 |
| CVE-2001-0129 | Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a lo… | HIGH | 10.0 | May 7, 2001 |
Showing 1 to 11 of 11 CVEs