Vulnerability Description
TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow monotonically by approximately 20 to 28 kB per request until the worker process is killed.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/theopaid/Unauthenticated-Memory-Leak-Leads-To-Memory-Exhausti
- https://www.vulncheck.com/advisories/tinyweb-memory-leak-dos-via-http-request-ha
FAQ
What is CVE-2026-67183?
CVE-2026-67183 is a vulnerability with a CVSS score of 7.5 (HIGH). TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpPars...
How severe is CVE-2026-67183?
CVE-2026-67183 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67183?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.