CVE-2026-2940 Details
Description
A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This affects the function tiny_web_server/tiny.c of the file tiny_web_server/tiny.c of the component URL Handler. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
A stack-based buffer overflow vulnerability has been identified in Zaher1307 tiny_web_server versions prior to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. The issue arises in the URL Handler component, specifically within the 'tiny_web_server/tiny.c' file. The vulnerability is caused by the unsafe use of the 'sprintf()' function, which writes user-controlled data into a fixed-size stack buffer without proper boundary checks. This flaw allows for out-of-bounds write operations, which can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 22, 2026CISA-ADP
Assessed Feb 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Zaher1307/tiny_web_server/ | [email protected] | ProductSource CodeVendor |
| https://github.com/Zaher1307/tiny_web_server/issues/1 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Zaher1307/tiny_web_server/issues/1#issue-3924357507 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.347312 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.347312 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.756036 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zaher1307 tiny_web_server | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 22, 2026 | New CVE Received | [email protected] |
Volerion