CVE-2026-67183

Source
https://cve.org/CVERecord?id=CVE-2026-67183
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67183.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67183
Published
2026-07-28T16:26:09Z
Modified
2026-10-08T02:51:37Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
Details

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow monotonically by approximately 20 to 28 kB per request until the worker process is killed.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-401"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67183.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.0.8"
                },
                {
                    "last_affected": "0.0.8"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/GeneralSandman/TinyWeb

Affected ranges

Type
GIT
Repo
https://github.com/GeneralSandman/TinyWeb
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67183.json"