CVE-2023-49606 - CVE House
Back to Database
Status published Critical CVE-2023-49606

A use-after-free vulnerability exists in the HTTP Connection Headers parsing...

Vulnerability Description

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-49606

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Discovered by Dimitrios Tatsis of Cisco Talos.

Affected Vendor

Affected Software

Tinyproxy
Vulnerable Versions:
1.11.1, Tinyproxy 1.10.0

Timeline

Official Publish: May 1st, 2024
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)