CVE-2025-12642 Details
Description
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: * Bypass access control rules * Inject unsafe input into backend logic that trusts request headers * Execute HTTP Request Smuggling attacks under some conditions This issue affects lighttpd1.4.80
A vulnerability in lighttpd version 1.4.80 allows for HTTP Header Smuggling attacks by incorrectly merging trailer fields into headers after parsing the HTTP request. This flaw can be exploited to bypass access control rules, inject unsafe input into backend logic that relies on request headers, and execute HTTP Request Smuggling attacks under certain conditions.
Users can upgrade to lighttpd version 1.4.81 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lighttpd/lighttpd1.4/commit/35cb89c103877de62d6b63d0804255475d77e5e1 | Toreon | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | Toreon |
Affected Products
| Product | Versions |
|---|---|
| lighttpd lighttpd | 1.4.80 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Toreon |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | New CVE Received | Toreon |