Loading vulnerability details…
CVSS v3.1
N/A
EPSS
3.53%
Published
Sep 27, 2008
Modified
Jun 16, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
Weaknesses (CWE)
Affected Products (54)
...and 4 more
References (20)