buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2025-63938
Component Overview
Vulnerability Overview
Name
CVE-2025-63938
Source
NVD (
link
)
Debian (
link
)
Description
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
CWEs
CWE-190
Published Date
Nov 26, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/rayinaw/my-hub/blob/main/CVE-2025-63938/DISCLOSURE.md
Third Party Advisory
https://github.com/tinyproxy/tinyproxy/commit/3c0fde94981b025271ffa1788ae425257841bf5a
Patch
https://github.com/tinyproxy/tinyproxy/issues/586
Exploit
Analysis
#
Affected Component
Analysis
tinyproxy
Patched
Vulnerability Ratings
#
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
tinyproxy
buildroot
master
1.11.2
Patched
tinyproxy
openwrt
master
1.11.1-r4
Exploitable
tinyproxy
openwrt
openwrt-25.12
1.11.1-r3
Exploitable
tinyproxy
yocto
kirkstone
1.11.0
Patched
tinyproxy
yocto
master
1.11.3
Not Affected
tinyproxy
yocto
scarthgap
1.11.1
Patched
Resolved with patches
#
tinyproxy (buildroot:2025.02.x)
#
Title
Author
Resolve
1
reqs: fix integer overflow in port number processing
rofl0r <rofl0r@users.noreply.github.com>
CVE-2025-63938
tinyproxy (buildroot:master)
#
Title
Author
Resolve
1
reqs: fix integer overflow in port number processing
rofl0r <rofl0r@users.noreply.github.com>
CVE-2025-63938
tinyproxy (yocto:kirkstone)
#
Title
Author
Resolve
1
reqs: fix integer overflow in port number processing
rofl0r <rofl0r@users.noreply.github.com>
CVE-2025-63938
tinyproxy (yocto:scarthgap)
#
Title
Author
Resolve
1
reqs: fix integer overflow in port number processing
rofl0r <rofl0r@users.noreply.github.com>
CVE-2025-63938