CVE-2026-29046Disclosure(ritlabs / tinyweb)

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch ritlabs tinyweb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and did not consistently defend against encoded forms such as %0d, %0a, and %00. This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. This issue has been patched in version 2.04.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-74CWE-93CWE-114

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinyweb

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
tinyweb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-06: 3Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 303-06
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical improper input validation & integer overflow in #TinyWeb #Win32 CVE-2026-29046 #CVE-2026-28497 CVSS: 9.3-9.2 An unauthenticated remote attacker can inject commands to perform HTTP Request Smuggling. #Patch #Patch #Patch

    Post summary

    The tweet alerts to critical integer overflow and input validation flaws in TinyWeb Win32 (CVE-2026-29046, CVE-2026-28497) that could allow HTTP Request Smuggling, and it signals that patches are available.

    01011223
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29046 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environme… https://www.cve.org/CVERecord?id=CVE-2026-29046

    Post summary

    CVE-2026-29046 involves improper header handling in TinyWeb, as disclosed on the CVE record; the post offers basic technical detail but no PoC, exploit, or patch information.

    00000119
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29046 - TinyWeb: HTTP Header Control Character Injection into CGI Environment Intel Report: https://ift.tt/Vs96ctW

    Post summary

    The alert announces CVE-2026-29046, a TinyWeb header control character injection flaw in the CGI environment, and includes an intel report link for more information.

    0000042
    343 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appritlabstinyweb---

Explore more