CVE-2025-41368
Multiple vulnerabilities in Small HTTP server by Smallsrv
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
4th
Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.
| CWE | CWE-22 |
| Vendor | smallsrv |
| Product | small http |
| Published | Mar 26, 2026 |
| Last Updated | Mar 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for smallsrv small http
Be the first to know when new unknown vulnerabilities affecting smallsrv small http are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Smallsrv / Small HTTP
3.06.36
References
Credits
Rafael Pedrero