๐Ÿ” CVE Alert

CVE-2025-41368

UNKNOWN 0.0

Multiple vulnerabilities in Small HTTP server by Smallsrv

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
4th

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.

CWE CWE-22
Vendor smallsrv
Product small http
Published Mar 26, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for smallsrv small http

Be the first to know when new unknown vulnerabilities affecting smallsrv small http are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Smallsrv / Small HTTP
3.06.36

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-small-http-server-smallsrv

Credits

Rafael Pedrero