In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade lighttpd | Mar 23, 2023 | Sep 12, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 12, 2022 |
| Debian | — | Upgrade lighttpd | Oct 4, 2022 | Sep 12, 2022 |
| Gentoo Linux | — | Upgrade www-servers/lighttpd. | Oct 31, 2022 | Sep 12, 2022 |
| Http Lighttpd | — | Upgrade to the latest version of lighttpd | Sep 19, 2024 | Sep 12, 2022 |
| Suse | — | Upgrade lighttpd-mod_vhostdb_pgsqlUpgrade lighttpd-mod_maxminddbUpgrade lighttpd-mod_authn_saslUpgrade lighttpd-mod_authn_gssapiUpgrade lighttpd-mod_vhostdb_mysqlUpgrade lighttpd-mod_authn_pamUpgrade lighttpd-mod_vhostdb_dbiUpgrade lighttpd-mod_webdavUpgrade lighttpd-mod_magnetUpgrade lighttpd-mod_vhostdb_ldapUpgrade lighttpdUpgrade lighttpd-mod_rrdtoolUpgrade lighttpd-mod_authn_ldap | Oct 26, 2022 | Sep 12, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Sep 12, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub