CVE-2026-55202
tinyproxy
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.
- CVSS
- 8.8
- EPSS
- 0.38% 30.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18