CVE-2025-41368: Smallsrv Small HTTP Server

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.

Affected products

  • Smallsrv Small HTTP Server: from 3.06.36, before 3.06.38 (fixed in 3.06.38)

Published 2026-03-26. Last modified 2026-06-17.