CVE-2022-40468: Tinyproxy Project Tinyproxy

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.

Affected products

Published 2022-09-19. Last modified 2026-06-17.