CVE-2026-55202

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
17/06/2026
Last modified:
14/07/2026

Description

Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.