CVE-2026-54388
Last modified
CVE-2026-54388 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54388?
How severe is CVE-2026-54388?
How do I fix CVE-2026-54388?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5437An out-of-bounds read vulnerability exists in `DicomStreamRe…7.5
- CVE-2026-54370acl before version 2.4.0 contains a time-of-check to time-of…7.2
- CVE-2026-54371attr before version 2.6.0 contains a symlink traversal vulne…8.4
- CVE-2026-5438A gzip decompression bomb vulnerability exists when Orthanc …7.5
- CVE-2026-54386marimo before 0.23.9 contains a reflected cross-site scripti…6.1
- CVE-2026-54387Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to …9.3
- CVE-2026-5439A memory exhaustion vulnerability exists in ZIP archive proc…7.5
- CVE-2026-54390JTL Shop versions 5.2.0 through 5.7.1 contains a server-side…9.8
- CVE-2026-54393A stored cross-site scripting vulnerability exists in MISP w…5.1
- CVE-2026-54394MISP contains a path traversal vulnerability in Organisation…5.3
- CVE-2026-54395MISP contains a reflected cross-site scripting vulnerability…5.3
- CVE-2026-54396An information disclosure vulnerability exists in the MISP A…5.3
Are you affected by CVE-2026-54388?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
