📦 Tinyweb

by Ritlabs

🔍 What is Tinyweb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-22781

CRITICAL CVSS 9.8 Jan 12, 2026

TinyWeb HTTP Server versions before 1.98 are vulnerable to unauthenticated remote command injection via CGI ISINDEX-style query parameters. Attackers can execute arbitrary OS commands on Windows serve...

CVE-2026-27630

HIGH CVSS 7.5 Feb 26, 2026

TinyWeb versions before 2.02 are vulnerable to Slowloris denial-of-service attacks where attackers can exhaust server resources by opening many connections and sending data extremely slowly. Anyone ho...

CVE-2024-5193

MEDIUM CVSS 5.3 May 22, 2024

This CVE describes a CRLF injection vulnerability in Ritlabs TinyWeb Server 1.94 that allows attackers to inject arbitrary HTTP headers or split responses by manipulating request inputs containing %0D...