CVE-2026-22903: Stack Overflow via SESSIONID Cookie in lighttpd
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22903?
CVE-2026-22903 is considered critical due to the potential for remote code execution and denial of service.
How do I fix CVE-2026-22903?
To fix CVE-2026-22903, you should update your lighttpd server to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-22903?
CVE-2026-22903 affects all versions of lighttpd that accept SESSIONID cookies and are unpatched.
What are the potential impacts of CVE-2026-22903?
The potential impacts of CVE-2026-22903 include server crashes and the likelihood of remote code execution exploits.
What can attackers achieve with CVE-2026-22903?
Attackers exploiting CVE-2026-22903 can execute arbitrary code on the affected server, compromising its security.