CVE-2025-41368

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:smallsrv:small_http_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-26 12:16

Updated : 2026-03-26 21:07


NVD link : CVE-2025-41368

Mitre link : CVE-2025-41368

CVE.ORG link : CVE-2025-41368


JSON object : View

Products Affected

smallsrv

  • small_http_server
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')