VendorsTinyproxy Projecttinyproxyany version
Vulnerabilities

Tinyproxy Project Tinyproxy any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-31842
Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling
Published 2026-04-07 · Modified
8.7EPSS 0.007
CVE-2022-40468
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
Published 2022-09-19 · Modified
7.5EPSS 0.019
CVE-2025-63938
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
Published 2025-11-26 · Analyzed
6.5EPSS 0.003
CVE-2017-11747
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tinyproxy.pid modification before a root script executes a "kill `cat /run/tinyproxy/tinyproxy.pid`" command.
Published 2017-07-30 · Modified
5.5EPSS 0.003