{"id":"CVE-2026-55202","summary":"Tinyproxy - Stathost Detection Bypass via Host Header Manipulation","details":"Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.","modified":"2026-08-12T16:41:18.755302Z","published":"2026-06-17T19:13:45.383Z","related":["openSUSE-SU-2026:11060-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55202.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55202.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55202"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/evil-winrm-path-traversal-in-download-dir-function"},{"type":"REPORT","url":"https://github.com/tinyproxy/tinyproxy/pull/606"},{"type":"FIX","url":"https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce"},{"type":"PACKAGE","url":"https://github.com/tinyproxy/tinyproxy"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tinyproxy/tinyproxy","events":[{"introduced":"0"},{"fixed":"baecbf4c3e006fa68ab92f65bbd4138c47ede111"},{"fixed":"09312a185ae25cc486b4ff5987638a7917a48bce"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.11.3"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["1.11.3","1.11.2","1.11.1","1.11.0","1.11.0-rc1","1.10.0","1.8.0","1.7.1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T16:41:18Z","vanir_signatures":[{"digest":{"line_hashes":["250361001829823527042340783168348133764","227835774662469510091333859774644194447","289824377013243884804482376383610791905","248660609267256382946417269283651519260","235970521266216829121234511744864248327","97049848007470513454998985262540600451","266142864002302138151520744026579050413","20212960294807539526026739228836300461","1828322513087709178416495673374747808","91594259662609552094428148158847614179","7568564077159191230356344988663101919","317476193158544306470389285842046340790","303061940764243613278629091426066516117","245222832016831967597885358906930985384","99773894593172070375287373074932138184","19075360101160639258609214584146232608","309331374853339442616482838865358055382","7261139467730362508502252283910414651","307854533813401952857890853822150879570"],"threshold":0.9},"id":"CVE-2026-55202-0f136a4b","signature_type":"Line","signature_version":"v1","source":"https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce","target":{"file":"src/reqs.c"},"deprecated":false},{"id":"CVE-2026-55202-b0015886","signature_type":"Function","signature_version":"v1","source":"https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce","target":{"file":"src/reqs.c","function":"handle_connection"},"deprecated":false,"digest":{"function_hash":"301418807004014581676958238819478343363","length":4792}},{"source":"https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce","target":{"file":"src/reqs.c","function":"process_request"},"deprecated":false,"digest":{"length":3924,"function_hash":"261962328238556657399583003071552788195"},"id":"CVE-2026-55202-ddf71274","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55202.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}