Smallsrv develops a lightweight HTTP server product characterized by a narrow vulnerability footprint centered on classic memory-safety and path-handling issues, including buffer overflows, path traversal, and unquoted search-path weaknesses typical of smaller-scale native implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smallsrv over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28994CRITICAL Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. | Apr 29, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-41368HIGH Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager a | Mar 26, 2026 | 8.1 | 27 | NO | NO |
CVE-2025-41359HIGH Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service' | Mar 26, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smallsrv.
Media articles that mention a CVE ID that affects a product developed by Smallsrv — matched by CVE ID, not by vendor name.