CVE-2026-3945

NameCVE-2026-3945
DescriptionAn integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without properly validating overflow conditions (e.g., errno == ERANGE).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1132498

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tinyproxy (PTS)bullseye1.10.0-5vulnerable
bullseye (security)1.10.0-5+deb11u1vulnerable
bookworm, bookworm (security)1.11.1-2.1+deb12u1vulnerable
trixie1.11.2-1vulnerable
forky, sid1.11.3-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tinyproxysource(unstable)(unfixed)1132498

Notes

[trixie] - tinyproxy <no-dsa> (Minor issue)
[bookworm] - tinyproxy <no-dsa> (Minor issue)
[bullseye] - tinyproxy <postponed> (Minor issue)
https://github.com/tinyproxy/tinyproxy/issues/602
https://github.com/tinyproxy/tinyproxy/pull/603

Search for package or bug name: Reporting problems