CVE-2023-49606 is a use-after-free vulnerability in Tinyproxy affecting versions 1.10.0 and 1.11.1. The flaw is in HTTP connection header parsing, specifically described by the maintainer as involving removal of the "connection" and "proxy-connection" headers in src/reqs.c within remove_connection_headers(). A specially crafted HTTP Connection header can cause previously freed memory to be reused, resulting in memory corruption. Reported outcomes include process crash/denial of service and potential remote code execution. The provided reporting also notes dispute over whether the vulnerable code path is reachable pre-authentication; one source states it is triggerable via an unauthenticated HTTP request, while the maintainer states the path is only reached after access-list checks and authentication succeed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-49606, a critical use-after-free vulnerability in Tinyproxy versions 1.11.1 and 1.10.0. The repository consists of two files: 'PoC.c', which implements the exploit logic, and 'README.md', which provides a detailed technical analysis of the vulnerability and affected versions. The exploit works by creating a crafted HTTP message with a large number of headers to trigger memory reallocation in Tinyproxy's header handling code. It then injects a malicious header containing a bash reverse shell payload, exploiting the use-after-free condition to achieve remote code execution. The PoC requires the attacker to specify their own IP and port for the reverse shell connection. The attack vector is network-based, requiring the ability to send HTTP requests to a vulnerable Tinyproxy instance. The endpoints in the code are placeholders and should be replaced with the attacker's actual IP and listener port. The repository is a functional PoC and not part of any exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical use-after-free memory corruption vulnerability in Tinyproxy (lightweight HTTP/S proxy) that can be triggered via crafted HTTP headers, leading to denial of service and potentially remote code execution.
A critical use-after-free vulnerability in Tinyproxy (HTTP/HTTPS proxy) that can be triggered via a specially crafted HTTP Connection header, leading to memory corruption and potentially unauthenticated remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.