VendorsRitlabstinyweball versions
Vulnerabilities

Ritlabs TinyWeb

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-22781
TinyWeb CGI Command Injection
Published 2026-01-12 · Analyzed
10.0EPSS 0.025
CVE-2026-27613
CGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)
Published 2026-02-25 · Analyzed
10.0EPSS 0.007
CVE-2026-28497
TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling)
Published 2026-03-06 · Analyzed
9.3EPSS 0.005
CVE-2026-29046
TinyWeb: HTTP Header Control Character Injection into CGI Environment
Published 2026-03-06 · Analyzed
9.2EPSS 0.004
CVE-2026-27630
TinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris)
Published 2026-02-25 · Analyzed
8.7EPSS 0.004
CVE-2026-27633
TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)
Published 2026-02-25 · Analyzed
8.7EPSS 0.004
CVE-2024-34199
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.
Published 2024-05-10 · Modified
8.6EPSS 0.012
CVE-2024-5193
Ritlabs TinyWeb Server Request crlf injection
Published 2024-05-22 · Modified
5.5EPSS 0.007