Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.
{
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55202.json",
"cwe_ids": [
"CWE-290"
]
}"2026-07-22T03:57:23Z"
[
{
"target": {
"file": "src/reqs.c"
},
"id": "CVE-2026-55202-0f136a4b",
"digest": {
"line_hashes": [
"250361001829823527042340783168348133764",
"227835774662469510091333859774644194447",
"289824377013243884804482376383610791905",
"248660609267256382946417269283651519260",
"235970521266216829121234511744864248327",
"97049848007470513454998985262540600451",
"266142864002302138151520744026579050413",
"20212960294807539526026739228836300461",
"1828322513087709178416495673374747808",
"91594259662609552094428148158847614179",
"7568564077159191230356344988663101919",
"317476193158544306470389285842046340790",
"303061940764243613278629091426066516117",
"245222832016831967597885358906930985384",
"99773894593172070375287373074932138184",
"19075360101160639258609214584146232608",
"309331374853339442616482838865358055382",
"7261139467730362508502252283910414651",
"307854533813401952857890853822150879570"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce"
},
{
"target": {
"function": "handle_connection",
"file": "src/reqs.c"
},
"id": "CVE-2026-55202-b0015886",
"digest": {
"function_hash": "301418807004014581676958238819478343363",
"length": 4792.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce"
},
{
"target": {
"function": "process_request",
"file": "src/reqs.c"
},
"id": "CVE-2026-55202-ddf71274",
"digest": {
"function_hash": "261962328238556657399583003071552788195",
"length": 3924.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55202.json"