Prevent request smuggling by rofl0r · Pull Request #610 · tinyproxy/tinyproxy · GitHub
Skip to content

Prevent request smuggling#610

Merged
rofl0r merged 2 commits into
tinyproxy:masterfrom
rofl0r:request_smuggling
May 7, 2026
Merged

Prevent request smuggling#610
rofl0r merged 2 commits into
tinyproxy:masterfrom
rofl0r:request_smuggling

Conversation

@rofl0r

@rofl0r rofl0r commented May 7, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@TristanInSec

Copy link
Copy Markdown

@rofl0r rofl0r force-pushed the request_smuggling branch from eae0686 to 6ed6fc9 Compare May 7, 2026 17:14
@rofl0r

rofl0r commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

ah sure, you're right.
force-pushed a fix, looking good now?

@TristanInSec

Copy link
Copy Markdown

Looks good, both findings are addressed now. Thanks for the quick turnaround!

@rofl0r rofl0r merged commit 364cdb6 into tinyproxy:master May 7, 2026
4 checks passed
@TristanInSec

Copy link
Copy Markdown

Same feedback: now that this is merged, would you be open to requesting CVE IDs? There are two distinct smuggling vectors (CL/TE desync and duplicate Content-Length), so ideally two CVEs. No rush -- happy to help with the process if needed.

@rofl0r

rofl0r commented May 9, 2026

Copy link
Copy Markdown
Contributor Author

would you be open to requesting CVE IDs?

i was under the impression that's something the security people can do on their own. so far it never needed my assistance to get CVEs assigned.

@TristanInSec

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants