CVE Feed

    Dashboard / CVE / CVE-2026-66753

    CVE-2026-66753

    tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient validation in header parsing and serialization. Attackers can exploit this injection primitive to perform response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against line-feed-tolerant backends.

    Published:Jul 28, 2026
    Last Modified:Aug 14, 2026
    EPS:Jul 28, 2026
    EPSS Score:0.00218
    CVSS Score:3.7

    Affected Products

    Vendor
    Tiny-http Project
    Product
    Tiny-http
    Vendor
    Tinyhttpd
    Product
    Tinyhttpd

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High