Skip to content
Critical HTTP Request Smuggling Vulnerabilities in Fedora Tinyproxy

Critical HTTP Request Smuggling Vulnerabilities in Fedora Tinyproxy

First seen 27 Jun 2026, 03:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 22:39 UTC

On June 18, 2026, Fedora released updates for tinyproxy addressing two critical HTTP Request Smuggling vulnerabilities, CVE-2026-54387 and CVE-2026-54388, both published on June 17, 2026. These vulnerabilities affect Fedora 43 and 44, allowing attackers to exploit CL/TE desynchronization and duplicate Content-Length headers. The flaws could lead to significant security risks, including unauthorized access and data manipulation. Users are urged to apply the updates immediately to mitigate potential exploitation. The updates can be installed using the 'dnf' package manager. The vulnerabilities were backported from upstream fixes by Carl George. The scope of impact includes all Fedora users running affected versions of tinyproxy. Current status indicates that patches are available and should be applied promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 104d ago How this analysis works

Timeline

2026-06-17
CVE-2026-54387 published
CVE-2026-54387 details an HTTP Request Smuggling vulnerability via CL/TE desynchronization.
Linuxsecurity
2026-06-17
CVE-2026-54388 published
CVE-2026-54388 describes an HTTP Request Smuggling vulnerability via duplicate Content-Length headers.
Linuxsecurity
2026-06-18
Fedora releases patches for tinyproxy
Updates addressing CVE-2026-54387 and CVE-2026-54388 were released for Fedora 43 and 44.
Linuxsecurity
2026-06-27
Articles published on tinyproxy vulnerabilities
Linuxsecurity published advisories detailing the critical vulnerabilities in tinyproxy affecting Fedora versions.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-54387 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed