CVE-2026-2940 details an out-of-bounds write vulnerability in the URL Handler component of Zaher1307 tiny_web_server, specifically in the tiny.c file up to commit 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This flaw, rated High severity with a CVSS score of 7.3, allows for remote exploitation without user interaction, potentially leading to low impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks Metasploit, Nuclei, or ExploitDB modules, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zaher1307 | Tiny Web Server | 8d77b1044a0ca3a5297d8726ac8aa2cf944d481bCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.