Ritlabs develops email and web server software with a focused product line centered on The Bat email client and TinyWeb web server, components that occupy a notable position despite modest production volume. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code; the recurring weakness classes span resource-exhaustion conditions, injection flaws across CRLF and OS-command contexts, and NVD placeholder categorizations that reflect the diversity of flaw types encountered. Defenders should monitor this vendor's advisories closely and prioritize patching for internet-facing server instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ritlabs over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22781CRITICAL TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query paramet | Jan 12, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-27613CRITICAL TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI | Feb 25, 2026 | 9.8 | 32 | NO | NO |
CVE-2001-0675MEDIUM Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is | Sep 20, 2001 | 5.0 | 29 | NO | YES |
CVE-2026-28497CRITICAL TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allow | Mar 6, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-29046HIGH TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables ( | Mar 6, 2026 | 8.2 | 26 | NO | NO |
CVE-2026-27633HIGH TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticate | Feb 26, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-27630HIGH TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server | Feb 26, 2026 | 7.5 | 25 | NO | NO |
CVE-2001-0398HIGH The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spac | Jun 18, 2001 | 7.5 | 24 | NO | NO |
CVE-2024-34199HIGH TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line. | May 14, 2024 | 8.6 | 23 | NO | NO |
CVE-2002-0338MEDIUM The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name. | Jun 25, 2002 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ritlabs.
Media articles that mention a CVE ID that affects a product developed by Ritlabs — matched by CVE ID, not by vendor name.