Tinyproxy

Vendor:

First CVE: Mar 12, 2001 · Active for 25 years

10
Total CVEs
More Total CVEs than 77% of tracked products
1.4
Avg CVEs / Year
Bottom 1%
8.1
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Tinyproxy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2001
25 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

CVE Severity & Scoring

Tinyproxy10 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network7 (70.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High0 (0.0%)
Unknown2 (20.0%)
User Interaction
None8 (80.0%)
Unknown2 (20.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None7 (70.0%)
Unknown2 (20.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previous
May 1, 20249.868NONO
Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.
Mar 12, 200110.041NOYES
Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to th
Jun 17, 20269.137NONO
Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend whi
Jun 17, 20269.136NONO
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page
Jun 17, 20268.233NONO
Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_tr
Apr 7, 20267.528NONO
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buff
Sep 19, 20227.525NONO
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
Nov 26, 20256.523NONO
tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free).
Aug 12, 20027.520NONO
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary p
Jul 30, 20175.519NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Tinyproxy

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.4.317.52.8%00
1.3.328.88.4%01
1.3.217.52.8%00
1.11.119.863.1%00
1.10.019.863.1%00