Back to CVE List

CVE-2026-54388

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Vulnerability Description

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-444
Source
NVD
Vendor
tinyproxy
Product
tinyproxy

External References

Discussion (0)

Add Comment

No comments yet. Be the first!