PT-2026-23629 · Tinyweb · Tinyweb
Maximmasiutin
·
Publicado
2026-03-06
·
Atualizado
2026-03-06
·
CVE-2026-28497
CVSS v4.0
9.3
Crítica
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TinyWeb versions prior to 2.03
Description
An integer overflow exists in the string-to-integer conversion routine (
Val). This allows a remote, unauthenticated attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. Successful exploitation can lead to unauthorized access, security filter bypass, and potential cache poisoning. The impact is critical for servers utilizing persistent connections (Keep-Alive).Recommendations
Update to version 2.03 or later.
Exploit
Correção
HTTP Request/Response Smuggling
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tinyweb