{"id":"CVE-2026-66752","summary":"tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling","details":"tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length. Attackers can exploit the discrepancy between tiny_http's improper Transfer-Encoding parsing and a correctly-implemented front-end proxy to produce two distinct interpretations of a single byte stream, enabling request smuggling, and can additionally send non-chunked bodies with non-chunked Transfer-Encoding values to cause failed body reads that tie up connections and consume worker threads without signaling errors to clients.","modified":"2026-08-01T03:32:57.019422197Z","published":"2026-07-28T15:44:41.573Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66752.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-444"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66752.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66752"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/tiny-http-http-request-smuggling-via-transfer-encoding-handling"},{"type":"PACKAGE","url":"https://github.com/tiny-http/tiny-http"},{"type":"EVIDENCE","url":"https://github.com/theopaid/HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tiny-http/tiny-http","events":[{"introduced":"0"},{"last_affected":"212b1c45852fef2093dc1374875a9393c55eb4b9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.12.0"}],"source":"AFFECTED_FIELD"}}],"versions":["0.12.0","0.11.0","v0.10.0","0.9.0","0.8.2","0.8.1","0.8.0","0.6.2","0.7.0","0.6.0","0.5.9","0.5.8","0.5.7","0.5.6","0.5.5","0.5.4","0.5.3","0.5.2","0.5.1","0.5.0","0.4.1","0.4.0","0.3.0","0.2.1","0.2.0","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66752.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L"}]}