CVE-2026-3945
EUVD-2026-1706630.03.2026, 08:16
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without properly validating overflow conditions (e.g., errno == ERANGE).Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tinyproxy_project | tinyproxy | 𝑥 ≤ 1.11.3 | CNA |
Debian Releases
Ubuntu Releases