Tinyproxy
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Tinyproxy, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Tinyproxy CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High5
- Medium4
- Low1
Latest CVEs
The 14 most recently published vulnerabilities affecting Tinyproxy.
- CVE-2026-54388Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers9.1
- CVE-2026-54387Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization9.1
- CVE-2026-55202Tinyproxy - Stathost Detection Bypass via Host Header Manipulation8.2
- CVE-2026-31842Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling7.5
- CVE-2026-3945tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service7.5
- CVE-2025-63938Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.6.5
- CVE-2023-49606A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, ...9.8
- CVE-2022-40468Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_re...7.5
- CVE-2017-11747main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by lever...5.5
- CVE-2012-3505Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2) a large number of forged headers that trigger ...5.0
- CVE-2011-1843Integer overflow in conf.c in Tinyproxy before 1.8.3 might allow remote attackers to bypass intended access restrictions in opportunistic circumstances via a TCP connection, related to improper han...6.8
- CVE-2011-1499acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the or...2.6
- CVE-2002-0847tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free).7.5
- CVE-2001-0129Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.10.0
Product grouping is registry-driven, with AI assist and human review. How it works