Metrics
Affected Vendors & Products
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tiny-http Project
Tiny-http Project tiny-http |
|
| CPEs | cpe:2.3:a:tiny-http_project:tiny-http:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Tiny-http Project
Tiny-http Project tiny-http |
Thu, 30 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinyhttpd
Tinyhttpd tinyhttpd |
|
| Vendors & Products |
Tinyhttpd
Tinyhttpd tinyhttpd |
Tue, 28 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length. Attackers can exploit the discrepancy between tiny_http's improper Transfer-Encoding parsing and a correctly-implemented front-end proxy to produce two distinct interpretations of a single byte stream, enabling request smuggling, and can additionally send non-chunked bodies with non-chunked Transfer-Encoding values to cause failed body reads that tie up connections and consume worker threads without signaling errors to clients. | |
| Title | tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-28T15:44:41.573Z
Updated: 2026-08-14T16:50:45.981Z
Reserved: 2026-07-27T16:27:47.648Z
Link: CVE-2026-66752
Updated: 2026-07-28T17:31:45.412Z
Status : Deferred
Published: 2026-07-28T16:20:16.887
Modified: 2026-07-30T20:03:32.983
Link: CVE-2026-66752
No data.