CVE-2025-12642
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
03/11/2025
Last modified:
12/11/2025
Description
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.<br />
<br />
Successful exploitation may allow an attacker to:<br />
<br />
* Bypass access control rules<br />
* Inject unsafe input into backend logic that trusts request headers<br />
* Execute HTTP Request Smuggling attacks under some conditions<br />
<br />
<br />
This issue affects lighttpd1.4.80
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:lighttpd:lighttpd:1.4.80:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



