{"id":"CVE-2022-30780","details":"Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.","modified":"2026-08-12T03:51:23.649556885Z","published":"2022-06-11T14:40:53Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30780.json"},"references":[{"type":"WEB","url":"https://podalirius.net/en/cves/2022-30780/"},{"type":"WEB","url":"https://redmine.lighttpd.net/issues/3059"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30780.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-30780"},{"type":"PACKAGE","url":"https://github.com/lighttpd/lighttpd1.4"},{"type":"PACKAGE","url":"https://github.com/p0dalirius/CVE-2022-30780-lighttpd-denial-of-service"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lighttpd/lighttpd1.4","events":[{"introduced":"b8e011d230c206503f072cce0c176da8a938cf00"},{"fixed":"992ba517abcfe9c162df0ba1383a051fe4ebd77c"}],"database_specific":{"extracted_events":[{"introduced":"1.4.56"},{"fixed":"1.4.58"},{"last_affected":"1.4.56"},{"introduced":"1.4.57"},{"last_affected":"1.4.57"},{"introduced":"1.4.58"},{"last_affected":"1.4.58"}],"source":["DESCRIPTION","CPE_STRING"],"cpe":["cpe:2.3:a:lighttpd:lighttpd:1.4.56:*:*:*:*:*:*:*","cpe:2.3:a:lighttpd:lighttpd:1.4.57:*:*:*:*:*:*:*","cpe:2.3:a:lighttpd:lighttpd:1.4.58:*:*:*:*:*:*:*"]}}],"versions":["1.4.56","1.4.57","1.4.58","lighttpd-1.4.57","lighttpd-1.4.56"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-30780.json"}}],"schema_version":"1.9.0"}