VYPR
Vendor

Tiny HTTP Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2017-16097HigJun 7, 2018
    risk 0.49cvss 7.5epss 0.02

    tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

  • CVE-2020-35884MedDec 31, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.