logo

Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution

ID: 75fea961-f32e-5f39-a7b9-dcbac0332188

STIX ID: report--75fea961-f32e-5f39-a7b9-dcbac0332188

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

More than 50% of 90,310 internet-exposed Tinyproxy hosts were found running versions vulnerable to CVE-2023-49606, a critical (CVSS 9.8) unauthenticated use-after-free that can enable remote code execution; Talos published a PoC and Tinyproxy maintainers have released version 1.11.2 as a patch, with guidance to update or avoid exposing the service publicly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.