📦 Lighttpd

by Lighttpd

🔍 What is Lighttpd?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-12642

CRITICAL CVSS 9.1 Nov 3, 2025

CVE-2025-12642 is an HTTP header smuggling vulnerability in lighttpd 1.4.80 where trailer fields are incorrectly merged into headers after HTTP request parsing. This allows attackers to bypass securit...

CVE-2022-30780

HIGH CVSS 7.5 Jun 11, 2022

A typo in Lighttpd's connection handling code causes the server to get stuck processing large HTTP headers, consuming CPU resources indefinitely. This allows remote attackers to cause denial of servic...