Skip to content
Noroxi

Tinyproxy Project records

5 published records for vendor tinyproxy project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
80%
Median publish → KEV
No record has entered KEV

All records

5 records
  • A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0.

    CriticalCVSS 9.8Proof of conceptEPSS 63%

    tinyproxy project · tinyproxyMay 1, 2024

  • Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling

    HighCVSS 8.7No exploitEPSS 1%

    tinyproxy project · tinyproxyApr 7, 2026

  • Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used.

    HighCVSS 7.5No exploitEPSS 2%

    tinyproxy project · tinyproxySep 19, 2022

  • Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

    MediumCVSS 6.5No exploitEPSS 0%

    tinyproxy project · tinyproxyNov 26, 2025

  • main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which mig

    MediumCVSS 5.5No exploitEPSS 0%

    tinyproxy project · tinyproxyJul 30, 2017