{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2023-49606/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tinyproxy_project:tinyproxy:1.10.0:*:*:*:*:*:*:*","cpe:2.3:a:tinyproxy_project:tinyproxy:1.11.1:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-49606"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Tinyproxy (1.10.0, 1.11.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve-2023-49606","use-after-free","proxy"],"_cs_type":"advisory","_cs_vendors":["Tinyproxy Project"],"content_html":"\u003cp\u003eCVE-2023-49606 is a critical use-after-free vulnerability affecting the Tinyproxy HTTP/S proxy server, specifically versions 1.10.0 and 1.11.1. The flaw resides within the \u003ccode\u003ehttp-message.c\u003c/code\u003e file, where the application manages memory allocation for HTTP header storage. When processing headers, specifically during the reallocation of memory for the header array, the application fails to safely handle pointers to old memory locations after they have been freed.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated remote attacker can supply crafted HTTP headers to trigger this memory corruption. Successful exploitation leads to a crash of the proxy process, resulting in a denial of service (DoS). Furthermore, due to the nature of use-after-free vulnerabilities in memory-unsafe environments, there is a potential for remote code execution (RCE) if an attacker can precisely manipulate the heap state. A proof-of-concept exploit script has been publicly disclosed on Sploitus, increasing the risk of exploitation for unpatched internet-facing proxy instances.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS score of 9.8, indicating high severity across confidentiality, integrity, and availability. Successful exploitation typically results in immediate service disruption (DoS). In environments where Tinyproxy is used as a gateway or intermediate proxy, potential RCE could grant attackers unauthorized access to the underlying server, facilitating lateral movement or further network compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately audit network infrastructure to identify all instances of Tinyproxy 1.10.0 and 1.11.1.\u003c/li\u003e\n\u003cli\u003ePatch or upgrade affected Tinyproxy instances to the latest available stable release that addresses CVE-2023-49606.\u003c/li\u003e\n\u003cli\u003eImplement ingress filtering on the proxy to block abnormally large or malformed HTTP header sequences if immediate patching is not feasible.\u003c/li\u003e\n\u003cli\u003eMonitor webserver and proxy error logs for frequent segmentation faults or abnormal process terminations associated with the Tinyproxy service.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T01:15:53Z","date_published":"2026-09-05T01:15:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-49606-tinyproxy-uaf/","summary":"A use-after-free vulnerability in Tinyproxy versions 1.10.0 and 1.11.1 permits unauthenticated remote attackers to trigger denial of service or potential remote code execution via malformed HTTP headers.","title":"Critical Use-After-Free Vulnerability in Tinyproxy","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-49606-tinyproxy-uaf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2023-49606","version":"https://jsonfeed.org/version/1.1"}