Back to overview

CVE-2026-67183

HIGH Exploitation: PoC
7.5
CVSS 3.1
Description
TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow monotonically by approximately 20 to 28 kB per request until the worker process is killed.

Metadata

CVE ID
CVE-2026-67183
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-28 16:06 UTC
Published
2026-07-28 16:26 UTC
Last updated
2026-07-28 17:22 UTC
Primary CWE
CWE-401
Missing Release of Memory after Effective Lifetime
Vendor / Product
GeneralSandman / TinyWeb
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
GeneralSandman TinyWeb — e48f15d38d2bebeec9cabcfdde81931b10a1963b ≤ a381da252fe8e873c8aff22703040426cc9b2ae0, 0.0.8
Weakness (CWE)
CWESourceDescription
CWE-401 cna Missing Release of Memory after Effective Lifetime
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview