CVE-2025-12642

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
03/11/2025
Last modified:
12/11/2025

Description

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.<br /> <br /> Successful exploitation may allow an attacker to:<br /> <br /> * Bypass access control rules<br /> * Inject unsafe input into backend logic that trusts request headers<br /> * Execute HTTP Request Smuggling attacks under some conditions<br /> <br /> <br /> This issue affects lighttpd1.4.80

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lighttpd:lighttpd:1.4.80:*:*:*:*:*:*:*