CVE-2025-63938

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
26/11/2025
Last modified:
02/01/2026

Description

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:* 1.11.2 (including)