Tinyproxy Project records
5 published records for vendor tinyproxy project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 80%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-190 Integer Overflow or Wraparound1
- CWE-269 Improper Privilege Management1
- CWE-416 Use After Free1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2023-49606Proof of concept | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0.tinyproxy project · tinyproxy · CWE-416 | Critical9.8 | — | 63.1% | May 1, 2024 |
34Monitor | CVE-2026-31842No exploit | Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handlingtinyproxy project · tinyproxy · CWE-444 | High8.7 | — | 0.7% | Apr 7, 2026 |
31Monitor | CVE-2022-40468No exploit | Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used.tinyproxy project · tinyproxy · CWE-1188 | High7.5 | — | 1.9% | Sep 19, 2022 |
26Monitor | CVE-2025-63938No exploit | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.tinyproxy project · tinyproxy · CWE-190 | Medium6.5 | — | 0.3% | Nov 26, 2025 |
22Monitor | CVE-2017-11747No exploit | main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which migtinyproxy project · tinyproxy · CWE-269 | Medium5.5 | — | 0.3% | Jul 30, 2017 |
- CVE-2023-4960658Plan
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0.
CriticalCVSS 9.8Proof of conceptEPSS 63%tinyproxy project · tinyproxyMay 1, 2024
- CVE-2026-3184234Monitor
Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling
HighCVSS 8.7No exploitEPSS 1%tinyproxy project · tinyproxyApr 7, 2026
- CVE-2022-4046831Monitor
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used.
HighCVSS 7.5No exploitEPSS 2%tinyproxy project · tinyproxySep 19, 2022
- CVE-2025-6393826Monitor
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
MediumCVSS 6.5No exploitEPSS 0%tinyproxy project · tinyproxyNov 26, 2025
- CVE-2017-1174722Monitor
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which mig
MediumCVSS 5.5No exploitEPSS 0%tinyproxy project · tinyproxyJul 30, 2017