Lighttpd is a lightweight, open-source web server designed for high-performance, resource-constrained deployments and embedded systems, and while narrowly focused as a single-product vendor, it occupies a prominent niche in the web infrastructure landscape. Vulnerabilities affecting the server frequently acquire public exploit code and encompass a meaningful share of serious-severity outcomes, concentrated in recurring weakness classes including path traversal, injection flaws, SQL injection, and information disclosure that are characteristic of HTTP request-handling and authentication logic. These vulnerability patterns reflect the complexity of safely parsing and validating untrusted network input in a performance-critical service, and the public-exploit tendency underscores the appeal of web servers as reconnaissance and initial-access targets. Defenders should monitor this vendor's releases closely despite its narrow footprint, particularly when deploying lighttpd in exposed or trust-boundary roles. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lighttpd over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11072CRITICAL lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact | Apr 10, 2019 | 9.8 | 72 | NO | NO |
CVE-2014-2323CRITICAL SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hos | Mar 14, 2014 | 9.8 | 68 | NO | YES |
CVE-2022-30780HIGH Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c h | Jun 11, 2022 | 7.5 | 56 | NO | NO |
CVE-2011-4362MEDIUM Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows | Dec 24, 2011 | 5.0 | 40 | NO | YES |
CVE-2007-3947MEDIUM request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request con | Jul 24, 2007 | 5.8 | 34 | NO | YES |
CVE-2012-5533MEDIUM The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header contai | Nov 24, 2012 | 5.0 | 33 | NO | YES |
CVE-2010-0295MEDIUM lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumpt | Feb 3, 2010 | 5.0 | 33 | NO | YES |
CVE-2008-1270MEDIUM mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by ac | Mar 10, 2008 | 5.0 | 33 | NO | YES |
CVE-2018-19052HIGH An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, w | Nov 7, 2018 | 7.5 | 30 | NO | NO |
CVE-2025-12642CRITICAL lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.
Successful explo | Nov 3, 2025 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lighttpd.
Media articles that mention a CVE ID that affects a product developed by Lighttpd — matched by CVE ID, not by vendor name.