PT-2026-50538 · Tinyproxy · Tinyproxy

·

CVE-2026-54387

·

Published

2026-06-17

·

Updated

2026-06-18

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tinyproxy versions prior to commit ff45d3b
Description Tinyproxy fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine the number of request body bytes to consume. This allows remote attackers to desynchronize the proxy and backend parser state, enabling the injection of arbitrary HTTP requests to the backend. This can lead to cache poisoning, access control bypass, and request hijacking. This issue is a form of HTTP Request Smuggling, where a discrepancy in how different servers interpret the end of a request allows a second request to be smuggled through.
Recommendations Update to the version containing commit ff45d3b.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54387
OPENSUSE-SU-2026:11060-1

Affected Products

Tinyproxy