Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lighttpd

First CVE: Feb 16, 2005Active for: 21 yearsTotal CVEs: 36
46.4
VTI Score
High

Lighttpd is a lightweight, open-source web server designed for high-performance, resource-constrained deployments and embedded systems, and while narrowly focused as a single-product vendor, it occupies a prominent niche in the web infrastructure landscape. Vulnerabilities affecting the server frequently acquire public exploit code and encompass a meaningful share of serious-severity outcomes, concentrated in recurring weakness classes including path traversal, injection flaws, SQL injection, and information disclosure that are characteristic of HTTP request-handling and authentication logic. These vulnerability patterns reflect the complexity of safely parsing and validating untrusted network input in a performance-critical service, and the public-exploit tendency underscores the appeal of web servers as reconnaissance and initial-access targets. Defenders should monitor this vendor's releases closely despite its narrow footprint, particularly when deploying lighttpd in exposed or trust-boundary roles. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lighttpd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2005
21 years ago
Most Recent CVE
Nov 3, 2025
263 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11072CRITICAL
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact
Apr 10, 20199.872NONO
CVE-2014-2323CRITICAL
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hos
Mar 14, 20149.868NOYES
CVE-2022-30780HIGH
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c h
Jun 11, 20227.556NONO
CVE-2011-4362MEDIUM
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows
Dec 24, 20115.040NOYES
CVE-2007-3947MEDIUM
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request con
Jul 24, 20075.834NOYES
CVE-2012-5533MEDIUM
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header contai
Nov 24, 20125.033NOYES
CVE-2010-0295MEDIUM
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumpt
Feb 3, 20105.033NOYES
CVE-2008-1270MEDIUM
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by ac
Mar 10, 20085.033NOYES
CVE-2018-19052HIGH
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, w
Nov 7, 20187.530NONO
CVE-2025-12642CRITICAL
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful explo
Nov 3, 20259.128NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
56%
31%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (30.6%)
Unknown25 (69.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (27.8%)
High1 (2.8%)
Unknown25 (69.4%)
User Interaction
None11 (30.6%)
Unknown25 (69.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (30.6%)
Unknown25 (69.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.8% of CVEs· 95th percentile
ExploitDB
5 CVEs
13.9% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lighttpd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lighttpd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lighttpd's Products

View all 5 CNAs →

Top CWEs