OVERVIEW CVE-2026-31842 is a HTTP request parsing desynchronization vulnerability affecting Tinyproxy through version 1.11.3. The vulnerability stems from a case-sensitive comparison of the Transfer-Encoding header in the is_chunked_transfer() function, which violates RFC 7230 specifications requiring case-insensitive header comparison. An attacker can exploit this by sending requests with "Transfer-Encoding: Chunked" (capitalized) to cause Tinyproxy to misinterpret the request as having no body, leading to inconsistent parsing between Tinyproxy and RFC-compliant backend servers. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication, low attack complexity, and high availability impact. The primary consequence is application-level denial of service through indefinite connection hangs that exhaust backend worker resources. A secondary impact exists in deployments using Tinyproxy for request inspection or security filtering, where the unread request body may bypass security controls without proper validation. The EPSS score of 0.00061 indicates this is currently a low-probability exploitation event. EXPLOITATION STATUS There is no current evidence of active exploitation, with the vulnerability not appearing on CISA's Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is marked as inactive on the Hot List, and no public exploit code availability has been reported. Community attention remains minimal based on available indicators, though the moderate FAUCET Risk Score of 48.0 suggests organizations should prioritize patching to prevent potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.11.3CPE match | cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:* | ||
<= 1.11.3CPE matchmatch criteria | cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.