CVE-2026-29046HIGH 8.2EPSS p30.4%
CVE-2026-29046CVE-2026-29046
Description
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and did not consistently defend against encoded forms such as %0d, %0a, and %00. This can enable header value confusion across parser boundaries and may create unsafe data in the CGI execution context. This issue has been patched in version 2.04.
Scoring
| CVSS 3.1 | 8.2 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
| EPSS | 0.39% probability of exploitation · percentile 30.4% · 2026-06-18T12:00:27Z |
| Published | 2026-03-06 |
| Last modified | 2026-03-16 |
Underlying weaknesses· 4
References
4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Process Controlcwe-114 | 0% | live |
| Weakness | Improper Input Validationcwe-20 | 0% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of CRLF Sequences ('CRLF Injection')cwe-93 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.