cbcvebase.
CVE-2021-3466
published 2021-03-25

CVE-2021-3466: A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.74%
94.5th percentile
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibmicrohttpd< libmicrohttpd 0.9.71-1 (bookworm)libmicrohttpd 0.9.71-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gnulibmicrohttpd
gnulibmicrohttpd
gnulibmicrohttpd>= 0 < 0.9.71-10.9.71-1
gnulibmicrohttpd>= 0 < 0.9.71-10.9.71-1
gnulibmicrohttpd>= 0 < 0.9.71-10.9.71-1
gnulibmicrohttpd>= 0 < 0.9.71-10.9.71-1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable function is `post_process_urlencoded` in libmicrohttpd — monitor for crashes or anomalous POST body processing in applications using this library, specifically on version 0.9.70.
  • Only libmicrohttpd version 0.9.70 is vulnerable; detection/triage should focus exclusively on deployments running this exact version.
  • ·Red Hat Enterprise Linux 6, 7, 8, and 9 ship versions of libmicrohttpd that predate the vulnerable code — these platforms are not affected and should be excluded from detection scope.
  • ·The vulnerability is fixed in libmicrohttpd 0.9.71; Debian-based systems patched to 0.9.71-1 (bookworm, bullseye, forky, sid, trixie) are no longer vulnerable.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.