7.5
CVSSv3

CVE-2022-41556

Published: 06/10/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A resource leak in gw_backend.c in lighttpd 1.4.56 up to and including 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lighttpd lighttpd

fedoraproject fedora 35

Vendor Advisories

Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint CVE-2022-37797 An invalid HTTP request (websocket handshake) may cause a NULL pointer dereference in the wstunnel module CVE-2022-41556 A resource leak in mod_fastcgi and mod_scgi could lead to a denial of service after a large num ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2822 lighttpd 1466-1 1467-1 Unknown Fixed githubcom/lighttpd/lighttpd14/pull/115 githubcom/lighttpd/lighttpd14/commit/bcddb ...