CVE-2025-12642: HTTP Header Smuggling via Trailer Merge
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.
Successful exploitation may allow an attacker to:
Bypass access control rules Inject unsafe input into backend logic that trusts request headers Execute HTTP Request Smuggling attacks under some conditions
This issue affects lighttpd1.4.80
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12642?
CVE-2025-12642 has a medium severity rating due to its potential for HTTP Header Smuggling attacks.
How do I fix CVE-2025-12642?
To fix CVE-2025-12642, update your Lighttpd server to the latest version where the vulnerability has been addressed.
What type of attack does CVE-2025-12642 enable?
CVE-2025-12642 enables HTTP Header Smuggling attacks, allowing attackers to manipulate HTTP headers.
Which software is affected by CVE-2025-12642?
CVE-2025-12642 affects Lighttpd version 1.4.80 and earlier versions.
Can CVE-2025-12642 lead to unauthorized access?
Yes, successful exploitation of CVE-2025-12642 can bypass access control rules, potentially leading to unauthorized access.