SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-67185

HIGH · CVSS 7.5 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

TinyWeb versions up to 0.0.8 are vulnerable to a path traversal flaw that enables unauthenticated attackers to access arbitrary files on the server by exploiting the URL path with ../ sequences. This could lead to the exposure of sensitive information, including credential stores and private keys, particularly if the server operates with root privileges. Organizations using TinyWeb should prioritize patching this vulnerability to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67185
Severity
HIGH
CVSS
7.5
EPSS
0.45%

Original NVD Description

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary checks. Attackers can craft a single request with ../ sequences that pass through the URL parser unchanged and reach the filesystem call via HttpFile::setFile(), exposing sensitive files such as credential stores and private keys when the server process runs as root.