Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 23 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tinyproxy
Tinyproxy tinyproxy |
|
| Vendors & Products |
Tinyproxy
Tinyproxy tinyproxy |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls. | |
| Title | Tinyproxy - Stathost Detection Bypass via Host Header Manipulation | |
| First Time appeared |
Tinyproxy Project
Tinyproxy Project tinyproxy |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tinyproxy Project
Tinyproxy Project tinyproxy |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-14T21:33:56.528Z
Reserved: 2026-06-16T15:53:37.764Z
Link: CVE-2026-55202
Updated: 2026-06-23T02:03:38.281Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T21:30:16Z