PT-2026-23629 · Tinyweb · Tinyweb

Maximmasiutin

·

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2026-28497

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TinyWeb versions prior to 2.03
Description An integer overflow exists in the string-to-integer conversion routine ( Val). This allows a remote, unauthenticated attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. Successful exploitation can lead to unauthorized access, security filter bypass, and potential cache poisoning. The impact is critical for servers utilizing persistent connections (Keep-Alive).
Recommendations Update to version 2.03 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-28497
GHSA-RP8J-CX7R-MW9F

Affected Products

Tinyweb