lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c
Published Apr 10, 2019
9.8
CRITICALCVSS 3.0
EPSS 73.76%
Description
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer states "The feature which can be abused to cause the crash is a new feature in lighttpd 1.4.50, and is not enabled by default. It must be explicitly configured in the config file (e.g. lighttpd.conf). Certain input will trigger an abort() in lighttpd when that feature is enabled. lighttpd detects the underflow or realloc() will fail (in both 32-bit and 64-bit executables), also detected in lighttpd. Either triggers an explicit abort() by lighttpd. This is not exploitable beyond triggering the explicit abort() with subsequent application exit.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 11, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (62 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 73.76% (0.73762) | 99.46th | v5 (v2026.06.15) |
| Sep 22, 2026 | 73.76% (0.73762) | 99.45th | v5 (v2026.06.15) |
| Sep 21, 2026 | 69.31% (0.69310) | 99.34th | v5 (v2026.06.15) |
| Sep 6, 2026 | 73.76% (0.73762) | 99.44th | v5 (v2026.06.15) |
| Sep 5, 2026 | 69.31% (0.69310) | 99.33th | v5 (v2026.06.15) |
| Aug 30, 2026 | 73.76% (0.73762) | 99.44th | v5 (v2026.06.15) |
| Aug 28, 2026 | 69.31% (0.69310) | 99.32th | v5 (v2026.06.15) |
| Aug 24, 2026 | 73.76% (0.73762) | 99.43th | v5 (v2026.06.15) |
| Aug 23, 2026 | 69.31% (0.69310) | 99.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 73.76% (0.73762) | 99.41th | v5 (v2026.06.15) |
| Mar 4, 2026 | 12.08% (0.12083) | 93.65th | v4 (v2025.03.14) |
| Mar 1, 2026 | 6.19% (0.06188) | 90.72th | v4 (v2025.03.14) |
| Feb 4, 2026 | 12.08% (0.12083) | 93.61th | v4 (v2025.03.14) |
| Feb 1, 2026 | 6.19% (0.06188) | 90.66th | v4 (v2025.03.14) |
| Jan 4, 2026 | 12.28% (0.12284) | 93.62th | v4 (v2025.03.14) |
| Jan 1, 2026 | 6.30% (0.06300) | 90.71th | v4 (v2025.03.14) |
| Dec 28, 2025 | 12.28% (0.12284) | 93.62th | v4 (v2025.03.14) |
| Dec 27, 2025 | 10.07% (0.10070) | 92.87th | v4 (v2025.03.14) |
| Dec 25, 2025 | 12.28% (0.12284) | 93.63th | v4 (v2025.03.14) |
| Dec 4, 2025 | 13.67% (0.13671) | 93.98th | v4 (v2025.03.14) |
| Dec 1, 2025 | 6.26% (0.06257) | 90.60th | v4 (v2025.03.14) |
| Nov 21, 2025 | 13.67% (0.13671) | 93.98th | v4 (v2025.03.14) |
| Nov 18, 2025 | 6.86% (0.06855) | 90.45th | v4 (v2025.03.14) |
| Nov 4, 2025 | 13.67% (0.13671) | 93.96th | v4 (v2025.03.14) |
| Nov 1, 2025 | 6.26% (0.06257) | 90.53th | v4 (v2025.03.14) |
| Oct 28, 2025 | 13.67% (0.13671) | 93.94th | v4 (v2025.03.14) |
| Oct 27, 2025 | 11.25% (0.11247) | 93.22th | v4 (v2025.03.14) |
| Oct 4, 2025 | 13.67% (0.13671) | 94.00th | v4 (v2025.03.14) |
| Oct 1, 2025 | 6.26% (0.06257) | 90.58th | v4 (v2025.03.14) |
| Sep 13, 2025 | 11.25% (0.11247) | 93.26th | v4 (v2025.03.14) |
| Sep 4, 2025 | 8.12% (0.08115) | 91.85th | v4 (v2025.03.14) |
| Sep 1, 2025 | 2.34% (0.02342) | 84.35th | v4 (v2025.03.14) |
| Aug 5, 2025 | 8.12% (0.08115) | 91.79th | v4 (v2025.03.14) |
| Aug 2, 2025 | 2.34% (0.02342) | 84.31th | v4 (v2025.03.14) |
| Aug 1, 2025 | 0.83% (0.00825) | 73.66th | v4 (v2025.03.14) |
| Jul 30, 2025 | 3.47% (0.03466) | 87.10th | v4 (v2025.03.14) |
| Jul 4, 2025 | 5.02% (0.05023) | 89.27th | v4 (v2025.03.14) |
| Jul 1, 2025 | 1.22% (0.01217) | 78.19th | v4 (v2025.03.14) |
| Jun 4, 2025 | 5.02% (0.05023) | 89.21th | v4 (v2025.03.14) |
| Jun 1, 2025 | 1.22% (0.01217) | 78.13th | v4 (v2025.03.14) |
| May 4, 2025 | 5.02% (0.05023) | 89.14th | v4 (v2025.03.14) |
| May 1, 2025 | 1.22% (0.01217) | 78.01th | v4 (v2025.03.14) |
| Apr 17, 2025 | 5.02% (0.05023) | 89.13th | v4 (v2025.03.14) |
| Apr 16, 2025 | 1.22% (0.01217) | 77.88th | v4 (v2025.03.14) |
| Mar 22, 2025 | 5.02% (0.05023) | 88.85th | v4 (v2025.03.14) |
| Mar 21, 2025 | 1.22% (0.01217) | 77.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.02% (0.05023) | 89.00th | v4 (v2025.03.14) |
| Dec 17, 2024 | 36.85% (0.36847) | 97.19th | v3 (v2023.03.01) |
| Aug 31, 2024 | 66.29% (0.66289) | 97.98th | v3 (v2023.03.01) |
| May 8, 2024 | 72.56% (0.72556) | 98.06th | v3 (v2023.03.01) |
| Apr 21, 2024 | 77.50% (0.77505) | 98.18th | v3 (v2023.03.01) |
| Apr 3, 2024 | 87.74% (0.87737) | 98.59th | v3 (v2023.03.01) |
| Feb 14, 2024 | 86.41% (0.86409) | 98.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 90.54% (0.90544) | 98.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.14% (0.01136) | 58.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.14% (0.01136) | 56.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.49% (0.12492) | 89.83th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.58% (0.05581) | 80.18th | v1 |
| Jan 6, 2022 | 5.58% (0.05581) | 79.98th | v1 |
| Sep 1, 2021 | 1.30% (0.01300) | 69.44th | v1 |
| Apr 14, 2021 | 1.30% (0.01300) | 0.00th | v1 |
References (3)
- http://www.securityfocus.com/bid/107907 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354 x_refsource_MISCPatchThird Party Advisory
- https://redmine.lighttpd.net/issues/2945 x_refsource_MISCExploitPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107907 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/lighttpd/lighttpd1.4/commit/32120d5b8b3203fc21ccb9eafb0eaf824bb59354 | x_refsource_MISCPatchThird Party Advisory | |
| https://redmine.lighttpd.net/issues/2945 | x_refsource_MISCExploitPatchThird Party Advisory |
Change history (0)
No recorded changes yet.