CVE-2026-66753

Source
https://cve.org/CVERecord?id=CVE-2026-66753
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66753.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-66753
Downstream
Published
2026-07-28T15:46:28.786Z
Modified
2026-07-30T04:03:32.650151698Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
Details

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient validation in header parsing and serialization. Attackers can exploit this injection primitive to perform response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against line-feed-tolerant backends.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/66xxx/CVE-2026-66753.json",
    "cwe_ids": [
        "CWE-113"
    ]
}
References

Affected packages

Git / github.com/tiny-http/tiny-http

Affected ranges

Type
GIT
Repo
https://github.com/tiny-http/tiny-http
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.12.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.1.0
0.1.1
0.11.0
0.12.0
0.2.0
0.2.1
0.3.0
0.4.0
0.4.1
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.2
0.7.0
0.8.0
0.8.1
0.8.2
0.9.0
v0.*
v0.10.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-66753.json"