A vulnerability identified as critical has been detected in Tinyproxy up to 1.11.2. The impacted element is the function strip_return_port of the file src/reqs.c. Performing manipulation results in integer overflow.

This vulnerability is known as CVE-2025-63938. Remote exploitation of the attack is possible. No exploit is available.