Vulnerability record · CVE-2023-49606 · published 1 May 2024
CVE-2023-49606: Tinyproxy HTTP header parsing use-after-free enables remote code execution
TTinyproxy Project · Tinyproxy
Tinyproxy 1.11.1 and 1.10.0 contain a use-after-free in HTTP Connection Headers parsing. A crafted HTTP header causes reuse of freed memory, leading to memory corruption that could result in remote code execution. The flaw is remotely reachable without authentication, making any exposed proxy instance a serious risk.
Description
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and public exploit references makes this a top remediation priority despite no KEV listing.
What it is
Tinyproxy 1.11.1 and 1.10.0 contain a use-after-free in HTTP Connection Headers parsing. A crafted HTTP header causes reuse of freed memory, leading to memory corruption that could result in remote code execution. The flaw is remotely reachable without authentication, making any exposed proxy instance a serious risk.
Impact
An unauthenticated attacker can corrupt memory in the proxy process and potentially execute arbitrary code in its context. That yields full compromise of the proxy host, including confidentiality, integrity and availability.
Attack surface
Reached over the network by sending a specially crafted HTTP request to the Tinyproxy service; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any instance reachable from untrusted networks is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.63 probability, 99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Upgrade Tinyproxy to a fixed release; the oss-security and Debian LTS references include patch information.
- If immediate patching is not possible, restrict proxy access to trusted networks and block untrusted inbound traffic to the Tinyproxy port.
- Run Tinyproxy as a low-privilege user and apply OS-level hardening to limit post-exploitation impact.
- Monitor vendor and distribution advisories for updated packages and apply them promptly.
Detection
- Inspect proxy and system logs for crashes, restarts or abnormal termination of the Tinyproxy process.
- Hunt for malformed or unusually long HTTP Connection header values in proxy request logs.
- Monitor for unexpected child processes or outbound connections originating from the Tinyproxy host.
- Use memory-safety tooling or crash dumps to identify use-after-free patterns in the Tinyproxy process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/05/07/1 | ExploitIssue TrackingMailing ListPatchThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889 | ExploitThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/05/07/1 | ExploitIssue TrackingMailing ListPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/09/msg00035.html | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889 | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1889 |
Track CVE-2023-49606 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-49606), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.