← Vulnerability feed

Vulnerability record · CVE-2023-49606 · published 1 May 2024

CVE-2023-49606: Tinyproxy HTTP header parsing use-after-free enables remote code execution

TTinyproxy Project · Tinyproxy

Tinyproxy 1.11.1 and 1.10.0 contain a use-after-free in HTTP Connection Headers parsing. A crafted HTTP header causes reuse of freed memory, leading to memory corruption that could result in remote code execution. The flaw is remotely reachable without authentication, making any exposed proxy instance a serious risk.

9.8 CVSS 3.1 Critical EPSS 63% · top 0.8% CWE-416 · Use after free
9.8CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication and public exploit references makes this a top remediation priority despite no KEV listing.

What it is

Tinyproxy 1.11.1 and 1.10.0 contain a use-after-free in HTTP Connection Headers parsing. A crafted HTTP header causes reuse of freed memory, leading to memory corruption that could result in remote code execution. The flaw is remotely reachable without authentication, making any exposed proxy instance a serious risk.

Impact

An unauthenticated attacker can corrupt memory in the proxy process and potentially execute arbitrary code in its context. That yields full compromise of the proxy host, including confidentiality, integrity and availability.

Attack surface

Reached over the network by sending a specially crafted HTTP request to the Tinyproxy service; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any instance reachable from untrusted networks is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.63 probability, 99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Upgrade Tinyproxy to a fixed release; the oss-security and Debian LTS references include patch information.
  • If immediate patching is not possible, restrict proxy access to trusted networks and block untrusted inbound traffic to the Tinyproxy port.
  • Run Tinyproxy as a low-privilege user and apply OS-level hardening to limit post-exploitation impact.
  • Monitor vendor and distribution advisories for updated packages and apply them promptly.

Detection

  • Inspect proxy and system logs for crashes, restarts or abnormal termination of the Tinyproxy process.
  • Hunt for malformed or unusually long HTTP Connection header values in proxy request logs.
  • Monitor for unexpected child processes or outbound connections originating from the Tinyproxy host.
  • Use memory-safety tooling or crash dumps to identify use-after-free patterns in the Tinyproxy process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49606 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-31842Tinyproxy project tinyproxy http request smuggling vulnerabilityTinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header i…EPSS 0.74%7.5CVE-2022-40468Tinyproxy project tinyproxy insecure default initialization vulnerabilityPotential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and…EPSS 1.9%6.5CVE-2025-63938Tinyproxy project tinyproxy integer overflow vulnerabilityTinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.EPSS 0.26%5.5CVE-2017-11747Tinyproxy project tinyproxy improper privilege management vulnerabilitymain.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow …EPSS 0.29%7.0CVE-2026-68820Windows Ancillary Function Driver for WinSock use-after-free privilege escalationThe Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free (CWE-416) that lets an authorized local attacker elevate privil…KEVEPSS 0.33%analysed8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed8.8CVE-2010-0249Microsoft Internet Explorer use-after-free enables remote code executionInternet Explorer 6, 7 and 8 mishandle objects in memory, leaving a dangling pointer that can be reused after the object is freed. A remote attacker …KEVEPSS 92%analysed7.8CVE-2020-9715Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat and Reader contain a use-after-free (CWE-416) flaw affecting versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and ea…KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2023-49606), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.