THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3945 (HIGH 7.5) — An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without

[NVD] CVE-2026-3945 (HIGH 7.5) — An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without

lownvdPublished 2026-03-30

CVE-2026-3945 CVSS: 7.5 HIGH Published: 2026-03-30T08:16:17.653

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol without properly validating overflow conditions (e.g., errno ==

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3945