CVE-2026-22904: Stack Overflow via Oversized Cookie Fields in lighttpd
Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22904?
CVE-2026-22904 is rated as a critical vulnerability due to its potential to cause denial-of-service conditions.
How do I fix CVE-2026-22904?
To fix CVE-2026-22904, update to the latest version of lighttpd where the vulnerability is patched.
Who is affected by CVE-2026-22904?
CVE-2026-22904 affects all versions of lighttpd that improperly handle oversized cookie fields.
What are the risks of CVE-2026-22904?
The risks of CVE-2026-22904 include denial-of-service attacks due to stack buffer overflow triggered by oversized cookie inputs.
Is CVE-2026-22904 remotely exploitable?
Yes, CVE-2026-22904 can be exploited by unauthenticated remote attackers.