Vulnerability record · CVE-2022-22707 · published 6 January 2022
CVE-2022-22707: Lighttpd out-of-bounds write vulnerability
Lighttpd · Lighttpd
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.
Description
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://redmine.lighttpd.net/issues/3134 | ExploitVendor Advisory |
| https://www.debian.org/security/2022/dsa-5040 | Third Party Advisory |
| https://redmine.lighttpd.net/issues/3134 | ExploitVendor Advisory |
| https://www.debian.org/security/2022/dsa-5040 | Third Party Advisory |
Track CVE-2022-22707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.