Tinyproxy Project
Tinyproxy Project Tinyproxy: vulnerabilities and CVEs
Tinyproxy Project Tinyproxy has 5 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31842 | High (8.7) | 0.74% | — | Apr 7, 2026 | Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer function uses strcmp to compare… |
| CVE-2025-63938 | Medium (6.5) | 0.26% | — | Nov 26, 2025 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c. |
| CVE-2023-49606 | Critical (9.8) | 63% | — | May 1, 2024 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory… |
| CVE-2022-40468 | High (7.5) | 1.9% | — | Sep 19, 2022 | Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function. |
| CVE-2017-11747 | Medium (5.5) | 0.29% | — | Jul 30, 2017 | main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this… |