{"id":"openSUSE-SU-2026:20456-1","summary":"Security update for tinyproxy","details":"This update for tinyproxy fixes the following issues:\n\nChanges in tinyproxy:\n\n- CVE-2026-3945: Fixed denial of service by unauthenticated remote attacker (boo#1261024)\n\n- Update to release 1.11.3\n  * conf: add BasicAuthRealm feature\n  * basic auth: fix error status 401 vs 407\n  * tinyproxy.conf.5: explain what a site_spec looks like\n  * tinyproxy.conf.5: add an IPv6 example to allow/deny section\n  * reqs: fix integer overflow in port number processing\n","modified":"2026-04-03T07:45:52.922713Z","published":"2026-04-01T16:15:06Z","related":["CVE-2026-3945"],"upstream":["CVE-2026-3945"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3945"}],"affected":[{"package":{"name":"tinyproxy","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tinyproxy&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.3-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"tinyproxy":"1.11.3-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20456-1.json"}}],"schema_version":"1.7.5"}