HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-67183 — TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthent...

·Source: NIST NVD

Updated:

Executive Summary

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worke

Analysis

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worker resident memory to grow monotonically by approximately 20 to 28 kB per request until the worker process is killed. CVSS Score: 7.5. Published: 2026-07-28T17:17:07.737.

Indicators of Compromise (1)

CVE (1)
CVE-2026-67183
Source Attribution

Originally published by NIST NVD on Jul 28, 2026. Verified by: NIST.

Related Threats