Critical Bug Could Open 50K+ Tinyproxy Servers to DoS, RCE
ID: 40398e0d-c7ea-5b98-888d-1a071ce49f30
STIX ID: report--40398e0d-c7ea-5b98-888d-1a071ce49f30
Feed Name: Dark Reading
Date Published: 2024-05-08
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A critical use-after-free vulnerability (CVE-2023-49606) in Tinyproxy (versions 1.11.1 and 1.10.0) can be triggered by specially crafted HTTP Connection headers to cause denial-of-service and potentially remote code execution. Censys/Cisco Talos analysis indicates tens of thousands of publicly exposed Tinyproxy instances with a majority potentially vulnerable; a proof-of-concept exploit was published by Talos while the Tinyproxy maintainer disputed some exploit details and published a fix. Administrators are advised to apply the maintainer's update, avoid exposing proxies to the public Internet, and enforce authentication or network restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
