Vendorstiny-http Projecttiny-httpall versions
Vulnerabilities

tiny-http Project tiny-http for Node.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-16097
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Published 2018-06-07 · Modified
7.5EPSS 0.020
CVE-2020-35884
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
Published 2020-12-31 · Modified
6.5EPSS 0.011