216.73.217.22

CVE-2025-12642

· Published 03/11/2025 20:17 · Modified 12/11/2025 14:34

Labels: CVE-2025-12642 1c6b5737-9389-4011-8117-89fa251edfb22025-11-03CVE-2025-12642CWE-444

Essential information

Published
03/11/2025 20:17
Modified
12/11/2025 14:34
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: * Bypass access control rules * Inject unsafe input into backend logic that trusts request headers * Execute HTTP Request Smuggling attacks under some conditions This issue affects lighttpd1.4.80

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
1c6b5737-9389-4011-8117-89fa251edfb2
NVD
View on NVD

Affected products (CPE)

ProductCPE
lighttpd / lighttpd cpe:2.3:a:lighttpd:lighttpd:1.4.80:*:*:*:*:*:*:*

References