Static Web Server is a modestly represented, narrowly scoped offering focused on serving static content, with a limited product portfolio centered on the single eponymous product. The vendor's disclosed vulnerabilities, though sparse in volume, reflect the core function and attack surface of a web-serving component; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Static Web Server over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67487HIGH Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to a | Dec 9, 2025 | 8.6 | 27 | NO | NO |
CVE-2026-27480MEDIUM Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerabilit | Feb 21, 2026 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Static Web Server.
Media articles that mention a CVE ID that affects a product developed by Static Web Server — matched by CVE ID, not by vendor name.