Denial of Service Vulnerability in lighttpd Web Server by Lighttpd
CVE-2022-41556
7.5HIGH
What is CVE-2022-41556?
A resource leak in lighttpd versions 1.4.56 to 1.4.66 arises from improper handling of RDHUP conditions during certain HTTP/1.1 chunked requests. This flaw can lead to connection-slot exhaustion when clients exhibit a significant amount of anomalous TCP behavior, potentially resulting in denial of service. The vulnerability has been addressed in version 1.4.67 of lighttpd.