{"id":"CVE-2022-34037","details":"An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.","modified":"2026-08-12T03:51:24.861052439Z","published":"2022-07-22T00:00:00Z","related":["openSUSE-SU-2022:10080-1","openSUSE-SU-2024:12220-1"],"database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34037.json","cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34037.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34037"},{"type":"REPORT","url":"https://github.com/caddyserver/caddy/issues/4775"},{"type":"REPORT","url":"https://github.com/caddyserver/caddy/issues/4775#issuecomment-1203388116"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/caddyserver/caddy","events":[{"introduced":"f7be0ee10131f25620a2f64af7e3ded43eae2049"},{"last_affected":"f7be0ee10131f25620a2f64af7e3ded43eae2049"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:caddyserver:caddy:2.5.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.5.1"},{"last_affected":"2.5.1"}]}}],"versions":["2.5.1","v2.5.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-34037.json"}}],"schema_version":"1.9.0"}