Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 3 vulnerabilities can now be installed.. # tinyproxy-1.11.3-3.1 on GA media Announcement ID: openSUSE-SU-2026:11060-1 Rating: moderate Cross-References: * CVE-2026-54387 * CVE-2026-54388 * CVE-2026-55202 Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the tinyproxy-1.11.3-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * tinyproxy 1.11.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54387.html * https://www.suse.com/security/cve/CVE-2026-54388.html * https://www.suse.com/security/cve/CVE-2026-55202.html . An update for openSUSE Tumbleweed fixes three vulnerabilities in tinyproxy version 1.11.3-3.1, enhancing system security.. OpenSUSE, tinyproxy, security update, system vulnerabilities, networking. . Severity: moderate. LinuxSecurity.com Team
Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9695fbdabb 2026-04-25 01:21:36.172703+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 44 Version : 1.11.2 Release : 7.fc44 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9695fbdabb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d67a979089 2026-04-22 11:41:11.030779+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 42 Version : 1.11.2 Release : 7.fc42 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite * Sat Jan 17 2026 Fedora Release Engineering - 1.11.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d67a979089' at the command line. For more information, refer to thednf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d8daf8790f 2026-04-22 07:48:13.354945+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 7.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Backport upstream fixes for CVE-2026-3945 and CVE-2026-31842. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Carl George - 1.11.2-7 - Backport upstream CVE fixes - Fixes CVE-2026-3945 - Fixes CVE-2026-31842 - Run upstream test suite * Sat Jan 17 2026 Fedora Release Engineering - 1.11.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452969 - CVE-2026-3945 tinyproxy: tinyproxy: Denial of Service via integer overflow in HTTP chunked transfer encoding parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452969 [ 2 ] Bug #2455913 - CVE-2026-31842 tinyproxy: HTTP Request parsing desynchronization via case-sensitive Transfer-Encoding handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455913 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d8daf8790f' at the command line. For more information, refer to thednf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for tinyproxy ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0111-1 Rating: important References: #1261024 Cross-References: CVE-2026-3945 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tinyproxy fixes the following issues: - CVE-2026-3945: Fixed denial of service by unauthenticated remote attacker (boo#1261024) - Update to release 1.11.3 * conf: add BasicAuthRealm feature * basic auth: fix error status 401 vs 407 * tinyproxy.conf.5: explain what a site_spec looks like * tinyproxy.conf.5: add an IPv6 example to allow/deny section * reqs: fix integer overflow in port number processing Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-111=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): tinyproxy-1.11.3-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2026-3945.html https://bugzilla.suse.com/1261024 . A critical update for openSUSE tinyproxy addresses denial of service vulnerability CVE-2026-3945. Apply patch now!. openSUSE Security Update, tinyproxy Denial of Service, CVE-2026-3945 Fix, SLE-15-SP7 Patch. . Severity: Important. LinuxSecurity.com Team
Add upstream patch to fix CVE-2025-63938.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a177cf4e1e 2025-12-11 01:00:50.567616+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 42 Version : 1.11.2 Release : 5.fc42 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Add upstream patch to fix CVE-2025-63938. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Carl George - 1.11.2-5 - Add upstream patch to fix CVE-2025-63938 * Fri Jul 25 2025 Fedora Release Engineering - 1.11.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417329 - CVE-2025-63938 tinyproxy: Tinyproxy integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417329 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a177cf4e1e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Add upstream patch to fix CVE-2025-63938.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-72fbf180c7 2025-12-04 00:51:14.440723+00:00 -------------------------------------------------------------------------------- Name : tinyproxy Product : Fedora 43 Version : 1.11.2 Release : 5.fc43 URL : https://tinyproxy.github.io/ Summary : A small, efficient HTTP/SSL proxy daemon Description : tinyproxy is a small, efficient HTTP/SSL proxy daemon that is very useful in a small network setting, where a larger proxy like Squid would either be too resource intensive, or a security risk. -------------------------------------------------------------------------------- Update Information: Add upstream patch to fix CVE-2025-63938. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Carl George - 1.11.2-5 - Add upstream patch to fix CVE-2025-63938 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417330 - CVE-2025-63938 tinyproxy: Tinyproxy integer overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2417330 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-72fbf180c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.. (CVE-2022-40468) A use-after-free vulnerability exists in the HTTP Connection Headers . MGASA-2025-0003 - Updated tinyproxy packages fix security vulnerabilities Publication date: 10 Jan 2025 URL: https://advisories.mageia.org/MGASA-2025-0003.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-40468, CVE-2023-49606 Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.. (CVE-2022-40468) A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability. (CVE-2023-49606) References: - https://bugs.mageia.org/show_bug.cgi?id=33206 - https://www.openwall.com/lists/oss-security/2024/05/07/1 - - - https://ubuntu.com/security/notices/USN-7140-1 - https://ubuntu.com/security/notices/USN-7190-1 - https://www.cve.org/CVERecord?id=CVE-2022-40468 - https://www.cve.org/CVERecord?id=CVE-2023-49606 SRPMS: - 9/core/tinyproxy-1.10.0-3.1.mga9 . The Mageia team has released updates for tinyproxy to fix severe security issues highlighted in advisory MGASA-2025-0003.. tinyproxy security, Mageia advisory, heap data leak, remote code execution. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.