216.73.217.22

CVE-2026-29046

· Published 06/03/2026 04:16 · Modified 06/03/2026 04:16

Labels: CVE-2026-29046 2026-03-06CVE-2026-29046CWE-20[email protected]

Essential information

Published
06/03/2026 04:16
Modified
06/03/2026 04:16
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and did not consistently defend against encoded forms such as %0d, %0a, and %00. This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. This issue has been patched in version 2.04.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tinyweb / tinyweb cpe:2.3:a:tinyweb:tinyweb:<2.04:*:*:*:*:*:*:*

References