High severity7.5NVD Advisory· Published Apr 7, 2026· Updated Aug 10, 2026
CVE-2026-31842
CVE-2026-31842
Description
Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer function uses strcmp to compare the header value against "chunked", even though RFC 7230 specifies that transfer-coding names are case-insensitive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- datatracker.ietf.org/doc/html/rfc7230nvdExploitTechnical Description
- github.com/tinyproxy/tinyproxy/issues/604nvdExploitIssue Tracking
News mentions
0No linked articles in our index yet.