Products: 1
Vulnerabilities: 37
Known Exploited: 0
3
Critical Level Threats
11
High Level Threats
20
Medium Level Threats
3
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-12642
HTTP Header Smuggling via Trailer Merge
Last Modified: Nov 12, 2025
Published: Nov 03, 2025
CVE-2025-8759
TRENDnet TN-200 Lighttpd hard-coded key
Last Modified: Jan 02, 2026
Published: Aug 09, 2025
CVE-2018-25103
Use-after-free vulnerabilities in lighttpd <= 1.4.50
Last Modified: Apr 15, 2026
Published: Jun 17, 2024
CVE-2022-41556
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
Last Modified: Nov 21, 2024
Published: Oct 06, 2022
CVE-2022-37797
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Last Modified: Nov 21, 2024
Published: Sep 12, 2022
Items Per Page
