Yaws is a lightweight open-source web server with a modestly represented but prominent vulnerability footprint, where disclosed flaws skew toward serious severity outcomes and frequently acquire public exploit code. The exposure centers on the core webserver product and recurs through input-handling and access-control weakness classes—path traversal, improper input validation, cross-site scripting, OS command injection, and XML external entity reference flaws—that are characteristic of web-facing services processing untrusted data. Defenders should treat Yaws instances as patching targets, particularly when exposed to the network; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yaws over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10974HIGH Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defe | Jul 7, 2017 | 7.5 | 79 | NO | YES |
CVE-2020-24916CRITICAL CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. | Sep 9, 2020 | 9.8 | 38 | NO | NO |
CVE-2011-4350MEDIUM Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files | Nov 26, 2019 | 6.5 | 38 | NO | YES |
CVE-2020-24379CRITICAL WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. | Sep 9, 2020 | 9.8 | 32 | NO | NO |
CVE-2010-4181MEDIUM Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences. | Nov 4, 2010 | 5.0 | 30 | NO | YES |
CVE-2009-0751MEDIUM Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers. | Mar 2, 2009 | 5.0 | 29 | NO | YES |
CVE-2011-5025MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to | Dec 29, 2011 | 4.3 | 26 | NO | YES |
CVE-2009-4495MEDIUM Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary comman | Jan 13, 2010 | 5.0 | 26 | NO | YES |
CVE-2020-12872MEDIUM yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with | May 15, 2020 | 5.5 | 20 | NO | NO |
CVE-2016-1000108MEDIUM yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data | Dec 10, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yaws.
Media articles that mention a CVE ID that affects a product developed by Yaws — matched by CVE ID, not by vendor name.