Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 43 tinyproxy Denial of Service CVE-2026-3945 and CVE-2026-31842 Fix

fedora
Calendar Grey April 22, 2026
Dist Fedora Esm H88
Explore the latest Fedora 43 tinyproxy update addressing crucial CVE fixes and security vulnerabilities.
Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.

Summary

tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a

small network setting, where a larger proxy like Squid would either be too

resource intensive, or a security risk.

Update Information:

Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.

Change Log

* Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite * Sat Jan 17 2026 Fedora Release Engineering - 1.11.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d8daf8790f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: tinyproxy
Product: Fedora 43
Version: 1.11.2
Release: 7.fc43
Summary: A small, efficient HTTP/SSL proxy daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here