Gnu Libmicrohttpd vulnerabilities

6 known vulnerabilities affecting gnu/libmicrohttpd.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-59777HIGHCVSS 8.7fixed in 2025-09-162025-11-10
CVE-2025-59777 [HIGH] CWE-476 CVE-2025-59777: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerabi NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
nvd
CVE-2025-62689HIGHCVSS 8.7fixed in 2025-09-162025-11-10
CVE-2025-62689 [HIGH] CWE-122 CVE-2025-62689: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerabi NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
nvd
CVE-2023-27371MEDIUMCVSS 5.9fixed in 0.9.762023-02-28
CVE-2023-27371 [MEDIUM] CWE-125 CVE-2023-27371: GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a m GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming
nvd
CVE-2021-3466CRITICALCVSS 9.8v0.9.702021-03-25
CVE-2021-3466 [CRITICAL] CWE-120 CVE-2021-3466: A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function le A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.
nvd
CVE-2013-7038MEDIUMCVSS 6.4≤ 0.9.31v0.9.16+14 more2013-12-13
CVE-2013-7038 [MEDIUM] CWE-119 CVE-2013-7038: The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read.
nvd
CVE-2013-7039MEDIUMCVSS 5.1≤ 0.9.31v0.9.16+14 more2013-12-13
CVE-2013-7039 [MEDIUM] CWE-119 CVE-2013-7039: Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, wh Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
nvd