CVE-2024-11148
Severity CVSS v4.0:
HIGH
Type:
CWE-476
NULL Pointer Dereference
Publication date:
05/12/2024
Last modified:
23/09/2025
Description
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* | 7.3 (excluding) | |
| cpe:2.3:o:openbsd:openbsd:7.3:*:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:-:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_001:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_002:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_003:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_004:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_005:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_006:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_007:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_008:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_009:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_010:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_011:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_012:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



