Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.

Project Subscriptions

Vendors Products
Smallsrv Subscribe
Small Http Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed in version V3.06.38.


Workaround

No workaround given by the vendor.

History

Thu, 26 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-428

Thu, 26 Mar 2026 12:45:00 +0000

Type Values Removed Values Added
Description Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access. Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.
Weaknesses CWE-22
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.
Title Multiple vulnerabilities in Small HTTP server by Smallsrv
First Time appeared Smallsrv
Smallsrv small Http
Weaknesses CWE-428
CPEs cpe:2.3:a:smallsrv:small_http:3.06.36:*:*:*:*:*:*:*
Vendors & Products Smallsrv
Smallsrv small Http
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-03-26T13:40:20.561Z

Reserved: 2025-04-16T09:57:06.080Z

Link: CVE-2025-41368

cve-icon Vulnrichment

Updated: 2026-03-26T13:40:16.762Z

cve-icon NVD

Status : Received

Published: 2026-03-26T12:16:08.583

Modified: 2026-03-26T13:16:25.457

Link: CVE-2025-41368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-26T13:54:50Z

Weaknesses