logo

Over 50,000 Tinyproxy servers vulnerable to critical RCE flaw

ID: 278b0fc1-2a21-503c-aff5-84e477adc36e

STIX ID: report--278b0fc1-2a21-503c-aff5-84e477adc36e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-05-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Tinyproxy CVE-2023-49606:** A critical use-after-free vulnerability in Tinyproxy (affecting versions 1.10.0 and 1.11.1) can be exploited via crafted HTTP Connection headers to crash servers and potentially achieve remote code execution; Talos published PoC exploits and Censys found a large number of internet-exposed instances that appear vulnerable, and maintainers released a patch in the master branch to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.