PT-2026-65523 · Tiny-Http · Tiny-Http

·

CVE-2026-66753

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions tiny-http versions prior to 0.12.1
Description Insufficient validation in header parsing and serialization allows the injection of carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides. This injection primitive can be used to perform response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against line-feed-tolerant backends.
Recommendations Update tiny-http to a version newer than 0.12.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66753

Affected Products

Tiny-Http