This is fork of original tiny-http.
A new development repo: codeberg
Because original authors does not respond on CVE and this crate is the only which is lightweight and actually working, I (hopefully) temporarily decided to fork the crate and keep development and support there.
The LICENSES which were initially were preserved and published under the same licenses.
V 0.12.7-crate
Since the crate was forked the following was implemented:
- fix CVE-2026-66753
- fix CVE-2026-66752
- merged ECONNABORTED triggers a server shutdown
- merged Handle ECONNABORTED errors from accept()
- merged fix: Make sure that the connection is indeed closed at the end of request but later rejected because it is breaking tests and this is a wrong way
- updated crate versions
- updated SSL/TLS subsystem
- code cleanup (partly)
AI (LLM) policy
- AI (LLM) generated sloppy code is prohibited. AI (LLM) generates slop "a priori" (anyway).
- It is strongly discouraged from using the AI based tools to write or enhance the code. AI slope would 100% violate the license by introducing the 3rd party licensed code. This code will never be accepted.
- It is ok to use the AI (LLM) for consultation purposes i.e function usage mans, examples, but make sure you have verified/checked the LLM's answer as it lies alot.
Tiny but strong HTTP server in Rust. Its main objectives are to be 100% compliant with the HTTP standard and to provide an easy way to create an HTTP server.
What does tiny-http handle?
- Accepting and managing connections to the clients
- Parsing requests
- Requests pipelining
- HTTPS (using either OpenSSL, Rustls or native-tls)
- Transfer-Encoding and Content-Encoding
- Turning user input (eg. POST input) into a contiguous UTF-8 string (not implemented yet)
- Ranges (not implemented yet)
Connection: upgrade(used by websockets)
Tiny-http handles everything that is related to client connections and data transfers and encoding.
Everything else (parsing the values of the headers, multipart data, routing, etags, cache-control, HTML templates, etc.) must be handled by your code. If you want to create a website in Rust, I strongly recommend using a framework instead of this library.
Add this to the Cargo.toml file of your project:
[dependencies]
tiny_http_fork = "0.11"use tiny_http_fork::{Server, Response};
let server = Server::http("0.0.0.0:8000").unwrap();
for request in server.incoming_requests() {
println!("received request! method: {:?}, url: {:?}, headers: {:?}",
request.method(),
request.url(),
request.headers()
);
let response = Response::from_string("hello world");
request.respond(response);
}Tiny-http was designed with speed in mind:
- Each client connection will be dispatched to a thread pool. Each thread will handle one client. If there is no thread available when a client connects, a new one is created. Threads that are idle for a long time (currently 5 seconds) will automatically die.
- If multiple requests from the same client are being pipelined (ie. multiple requests
are sent without waiting for the answer), tiny-http will read them all at once and they will
all be available via
server.recv(). Tiny-http will automatically rearrange the responses so that they are sent in the right order. - One exception to the previous statement exists when a request has a large body (currently > 1kB), in which case the request handler will read the body directly from the stream and tiny-http will wait for it to be read before processing the next request. Tiny-http will never wait for a request to be answered to read the next one.
- When a client connection has sent its last request (by sending
Connection: closeheader), the thread will immediately stop reading from this client and can be reclaimed, even when the request has not yet been answered. The reading part of the socket will also be immediately closed. - Decoding the client's request is done lazily. If you don't read the request's body, it will not be decoded.
Examples of tiny-http in use:
- heroku-tiny-http-hello-world - A simple web application demonstrating how to deploy tiny-http to Heroku
- crate-deps - A web service that generates images of dependency graphs for crates hosted on crates.io
- rouille - Web framework built on tiny-http
This project is licensed under either of
- Apache License, Version 2.0, (LICENSE-APACHE or http://www.apache.org/licenses/LICENSE-2.0)
- MIT license (LICENSE-MIT or http://opensource.org/licenses/MIT)
at your option.
Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in tiny-http by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.
