CVE-2026-55202
Last modified
CVE-2026-55202 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55202?
How severe is CVE-2026-55202?
How do I fix CVE-2026-55202?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55196Hermes WebUI before 0.51.409 contains an authentication bypa…9.1
- CVE-2026-55197Hermes WebUI before 0.51.443 contains a broken access contro…7.1
- CVE-2026-55198Hermes WebUI before 0.51.443 contains an authorization bypas…7.1
- CVE-2026-55199libssh2 through 1.11.1, fixed in commit 1762685, contains a …7.5
- CVE-2026-55200libssh2 through 1.11.1, fixed in commit 7acf3df contains an …8.3
- CVE-2026-55201Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a …7.4
- CVE-2026-55203HAProxy through 3.4.0, fixed in commit 5985276, contains an …9.1
- CVE-2026-55204HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a …8.7
- CVE-2026-55205Hermes WebUI before 0.51.468 contains a resource exhaustion …6.9
- CVE-2026-55206py7zr is a Python-based library and utility to support 7zip …8.7
- CVE-2026-55207Pimcore is an Open Source Data & Experience Management Platf…8.8
- CVE-2026-55208Pimcore Studio Backend Bundle is the backend bundle for Pimc…7.7
Are you affected by CVE-2026-55202?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
