Bug 2412046 (CVE-2025-12642) - CVE-2025-12642 lighthttpd: HTTP Header Smuggling via Trailer Merge
Summary: CVE-2025-12642 lighthttpd: HTTP Header Smuggling via Trailer Merge
Keywords:
Status: NEW
Alias: CVE-2025-12642
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2412439 2412440 2412441
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-03 20:03 UTC by OSIDB Bzimport
Modified: 2025-11-05 09:04 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-03 20:03:44 UTC
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.

Successful exploitation may allow an attacker to:

  *  Bypass access control rules
  *  Inject unsafe input into backend logic that trusts request headers
  *  Execute HTTP Request Smuggling attacks under some conditions


This issue affects lighttpd1.4.80


Note You need to log in before you can comment on or make changes to this bug.