CVE-2025-41368

HIGH

Small HTTP Server 3.06.36 - Authenticated Path Traversal

Title source: manual
STIX 2.1

Description

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.

Scores

CVSS v3 8.1
EPSS 0.0061
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
Smallsrv/Small HTTP 3.06.36
smallsrv/small_http_server 3.06.36 - 3.06.38
Published Mar 26, 2026
Tracked Since Mar 26, 2026