CVE-2025-63938

Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:*

History

02 Jan 2026, 20:48

Type Values Removed Values Added
CPE cpe:2.3:a:tinyproxy_project:tinyproxy:*:*:*:*:*:*:*:*
First Time Tinyproxy Project tinyproxy
Tinyproxy Project
References () https://github.com/rayinaw/my-hub/blob/main/CVE-2025-63938/DISCLOSURE.md - () https://github.com/rayinaw/my-hub/blob/main/CVE-2025-63938/DISCLOSURE.md - Third Party Advisory
References () https://github.com/tinyproxy/tinyproxy/commit/3c0fde94981b025271ffa1788ae425257841bf5a - () https://github.com/tinyproxy/tinyproxy/commit/3c0fde94981b025271ffa1788ae425257841bf5a - Patch
References () https://github.com/tinyproxy/tinyproxy/issues/586 - () https://github.com/tinyproxy/tinyproxy/issues/586 - Exploit, Issue Tracking, Patch

26 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-26 17:15

Updated : 2026-01-02 20:48


NVD link : CVE-2025-63938

Mitre link : CVE-2025-63938

CVE.ORG link : CVE-2025-63938


JSON object : View

Products Affected

tinyproxy_project

  • tinyproxy
CWE
CWE-190

Integer Overflow or Wraparound