Cherokee is a lightweight, open-source web server whose vulnerability profile centers on its HTTP daemon implementation and recurs through path-traversal and directory-restriction bypass weaknesses characteristic of web-server request-handling logic. The vendor's disclosures frequently acquire public exploit tooling, making this a product where disclosed flaws tend to reach weaponized form. Defenders running Cherokee should prioritize patching and restrict server exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cherokee over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1097HIGH Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a d | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2019-20800CRITICAL In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstra | May 18, 2020 | 9.8 | 31 | NO | NO |
CVE-2009-4489MEDIUM header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibl | Jan 13, 2010 | 5.0 | 28 | NO | YES |
CVE-2019-20798HIGH An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the we | May 18, 2020 | 8.4 | 27 | NO | NO |
CVE-2019-20799HIGH In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server. | May 18, 2020 | 7.5 | 26 | NO | NO |
CVE-2009-4587MEDIUM Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word. | Jan 7, 2010 | 5.0 | 26 | NO | YES |
CVE-2009-3902MEDIUM Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the U | Nov 6, 2009 | 5.0 | 25 | NO | YES |
CVE-2019-1010218HIGH Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee | Jul 22, 2019 | 7.5 | 23 | NO | NO |
CVE-2011-2191MEDIUM Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that | Oct 7, 2011 | 6.8 | 23 | NO | NO |
CVE-2006-1681MEDIUM Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an | Apr 11, 2006 | 4.3 | 23 | NO | YES |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cherokee.
Media articles that mention a CVE ID that affects a product developed by Cherokee — matched by CVE ID, not by vendor name.