CVE-2026-31842Disclosure(tinyproxy_project / tinyproxy)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tinyproxy_project tinyproxy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer function uses strcmp to compare the header value against "chunked", even though RFC 7230 specifies that transfer-coding names are case-insensitive.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinyproxy

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
tinyproxy

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 1Mentions · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 1Technical Details · 2026-05-01: 104-0704-1905-01
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-191
Disclosure1
2026-05-011
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-31842 (CVSS 7.5) Tinyproxy ≤1.11.3 vulnerable to HTTP request smuggling via case-sensitive Transfer-Encoding parsing. Enables DoS & security control bypass. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/jEKt8LTAz1

    Post summary

    The tweet alerts to a high‑severity HTTP request smuggling flaw in Tinyproxy 1.11.3 or earlier, urges immediate patching, and provides basic vulnerability details.

    0000034
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31842 Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The… https://www.cve.org/CVERecord?id=CVE-2026-31842

    Post summary

    The text announces the disclosure of CVE-2026-31842, detailing a parsing desynchronization flaw in Tinyproxy 1.11.3 tied to Transfer-Encoding handling.

    00000191
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31842 HTTP Request Parsing Desynchronization in Tinyproxy Through 1.11.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31842

    Post summary

    A new desynchronization vulnerability (CVE-2026-31842) affecting Tinyproxy up to version 1.11.3 has been disclosed, with technical details but no PoC, exploit code, or patch information provided.

    0000045
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31842 - Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling Intel Report: https://ift.tt/f8Es6XF

    Post summary

    The alert announces a new vulnerability (CVE‑2026‑31842) in Tinyproxy, detailing a desynchronization issue in HTTP request parsing; no PoC, exploit, patch, or active exploitation information is shared.

    0000025
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptinyproxy_projecttinyproxy---

Explore more