THREAT OPS › Threat News › [NVD] CVE-2026-3945 (HIGH 7.5) — An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without
[NVD] CVE-2026-3945 (HIGH 7.5) — An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without
CVE-2026-3945 CVSS: 7.5 HIGH Published: 2026-03-30T08:16:17.653
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without properly validating overflow conditions (e.g., errno ==
Indicators of compromise
- CVE-2026-3945cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3945