PT-2026-50530 · Tinyproxy · Tinyproxy

·

CVE-2026-55202

·

Published

2026-06-17

·

Updated

2026-06-23

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tinyproxy versions prior to 1.11.3 commit 09312a1
Description Improper validation of the Host header during stathost detection allows unauthenticated attackers to access the statistics page by injecting a matching Host header or bypassing detection through port manipulation. This can lead to unauthorized access to internal proxy statistics or the misrouting of requests as transparent proxy connections to circumvent access controls.
Recommendations Update to the version containing commit 09312a1.

Exploit

Fix

HTTP Request/Response Smuggling

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55202
OPENSUSE-SU-2026:11060-1

Affected Products

Tinyproxy