← volver
CVE-2025-12642

HTTP Header Smuggling via Trailer Merge

CVSS 6.9 MEDIUMEPSS 0.3%CWE-444
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: * Bypass access control rules * Inject unsafe input into backend logic that trusts request headers * Execute HTTP Request Smuggling attacks under some conditions This issue affects lighttpd1.4.80
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Productos afectados
lighttpd · lighttpd

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →