CVE-2025-63938: Integer Overflow
Published Nov 26, 2025
·Updated
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the stripreturnport() function within src/reqs.c.
Affected Software
2 affected components
tinyproxy tinyproxy<1.11.2
Tinyproxy Project Tinyproxy<=1.11.2
Remediation
Patch Available
Event History
Nov 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63938?
CVE-2025-63938 is classified as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2025-63938?
To mitigate CVE-2025-63938, update Tinyproxy to version 1.11.3 or later where the vulnerability is patched.
3
What impact does CVE-2025-63938 have on Tinyproxy users?
CVE-2025-63938 could allow an attacker to exploit the integer overflow for potentially malicious actions, compromising the Tinyproxy service.
4
When was CVE-2025-63938 disclosed?
CVE-2025-63938 was disclosed as of October 2025, prompting immediate attention from Tinyproxy users.
5
Is CVE-2025-63938 a local or remote vulnerability?
CVE-2025-63938 is considered a remote vulnerability that can be exploited without local access to the affected system.