CVE-2022-30780
Dashboard / Vulnerabilities / CVE-2022-30780
CVE-2022-30780
Published: 11 Jun 2022Last Modified: 12 Aug 2026
Summary:
Details: Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.
References: https://podalirius.net/en/cves/2022-30780/, https://redmine.lighttpd.net/issues/3059, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30780.json, https://nvd.nist.gov/vuln/detail/CVE-2022-30780, https://github.com/lighttpd/lighttpd1.4, https://github.com/p0dalirius/CVE-2022-30780-lighttpd-denial-of-service
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- b8e011d230c206503f072cce0c176da8a938cf00
Affected versions
1.4.56
1.4.57
1.4.58
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
