PT-2026-23630 · Tinyweb · Tinyweb
Maximmasiutin
·
Published
2026-03-06
·
Updated
2026-03-16
·
CVE-2026-29046
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
TinyWeb versions prior to 2.04
Description
TinyWeb, a web server for Win32, is susceptible to a header value confusion issue due to insufficient sanitization of control characters (CR, LF, and NUL, including encoded forms like %0d, %0a, and %00) within HTTP request headers. The parser's failure to strictly reject these characters and consistently defend against encoded forms can lead to unsafe data being introduced into the CGI execution context via HTTP * environment variables. This could potentially enable malicious manipulation of CGI processes.
Recommendations
Update to version 2.04 or later.
Exploit
Fix
Special Elements Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tinyweb