Sthttpd is a lightweight, embeddable HTTP server used in embedded systems and resource-constrained environments, with a narrow but durable vulnerability footprint concentrated in its core server product. The observed weakness classes center on memory-safety issues, particularly improper buffer restrictions and out-of-bounds writes, typical of C-based network daemons handling untrusted input at scale.
The number and severity of CVEs published that impact products developed by Sthttpd Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26843HIGH An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon cra | Feb 7, 2021 | 7.5 | 23 | NO | NO |
CVE-2017-10671HIGH Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have uns | Jun 29, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sthttpd Project.
Media articles that mention a CVE ID that affects a product developed by Sthttpd Project — matched by CVE ID, not by vendor name.