Lighttpd

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 37
    Known Exploited: 0
    3
    Critical Level Threats
    11
    High Level Threats
    20
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-12642

    HTTP Header Smuggling via Trailer Merge

    Last Modified: Nov 12, 2025
    Published: Nov 03, 2025

    CVE-2025-8759

    TRENDnet TN-200 Lighttpd hard-coded key

    Last Modified: Jan 02, 2026
    Published: Aug 09, 2025

    CVE-2018-25103

    Use-after-free vulnerabilities in lighttpd <= 1.4.50

    Last Modified: Apr 15, 2026
    Published: Jun 17, 2024

    CVE-2022-41556

    A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.

    Last Modified: Nov 21, 2024
    Published: Oct 06, 2022

    CVE-2022-37797

    In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.

    Last Modified: Nov 21, 2024
    Published: Sep 12, 2022
    Items Per Page
    Lighttpd Vulnerabilities & Security CVEs | CVE-DB