216.73.217.22

CVE-2026-28497

· Published 06/03/2026 04:16 · Modified 06/03/2026 04:16

Labels: CVE-2026-28497 2026-03-06CVE-2026-28497CWE-190[email protected]

Essential information

Published
06/03/2026 04:16
Modified
06/03/2026 04:16
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. This can lead to unauthorized access, security filter bypass, and potential cache poisoning. The impact is critical for servers using persistent connections (Keep-Alive). This issue has been patched in version 2.03.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tinyweb / tinyweb cpe:2.3:a:tinyweb:tinyweb:<2.03:*:*:*:*:*:*:*

References