CVE-2026-2940Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This affects the function tiny_web_server/tiny.c of the file tiny_web_server/tiny.c of the component URL Handler. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-22); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-22: 2Mentions · 2026-02-27: 1Technical Details · 2026-02-22: 2Technical Details · 2026-02-27: 102-2202-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-222
Disclosure2
2026-02-271
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2940 Remote Out-of-Bounds Write Vulnerability in Zaher1307 Tiny Web Server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2940

    Post summary

    A remote out-of-bounds write vulnerability (CVE-2026-2940) has been identified in Zaher1307 Tiny Web Server, with no evidence of exploitation, PoC, or patch information provided.

    0001041
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2940 (CVSS:6.9, HIGH) is Awaiting Analysis. A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This affects..https://nvd.nist.gov/vuln/detail/CVE-2026-2940 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑2940 with a CVSS score of 6.9 and notes it is awaiting analysis, but does not provide exploit details or patch information.

    0000015
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2940 A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This affects the function tiny_web_server/tiny.c of the file… https://www.cve.org/CVERecord?id=CVE-2026-2940

    Post summary

    A new vulnerability, CVE-2026-2940, has been identified in Zaher1307 tiny_web_server, affecting the tiny.c function. No PoC, exploit, or patch information is provided.

    00000100
    56.5K followersView on X

Explore more