CVE-2026-28497Disclosure(ritlabs / tinyweb)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. This can lead to unauthorized access, security filter bypass, and potential cache poisoning. The impact is critical for servers using persistent connections (Keep-Alive). This issue has been patched in version 2.03.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinyweb

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
tinyweb

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-06: 2Technical Details · 2026-03-06: 203-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical improper input validation & integer overflow in #TinyWeb #Win32 CVE-2026-29046 #CVE-2026-28497 CVSS: 9.3-9.2 An unauthenticated remote attacker can inject commands to perform HTTP Request Smuggling. #Patch #Patch #Patch

    Post summary

    The message announces two critical TinyWeb Win32 CVEs involving improper input validation and integer overflow, enabling remote command injection via HTTP request smuggling, and stresses the need for patching.

    01011223
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28497 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routin… https://www.cve.org/CVERecord?id=CVE-2026-28497

    Post summary

    The content announces CVE‑2026‑28497 and notes an integer‑overflow vulnerability in TinyWeb, but lacks any PoC, exploit, or mitigation details.

    00000125
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appritlabstinyweb---

Explore more