{"id":"CVE-2022-38668","details":"HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.","modified":"2026-08-12T13:32:11.327981Z","published":"2022-08-22T19:06:02Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38668.json"},"references":[{"type":"WEB","url":"https://github.com/0xhebi/CVEs/blob/main/Crow/CVE-2022-38668.md"},{"type":"WEB","url":"https://gynvael.coldwind.pl/?id=752"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38668.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38668"},{"type":"FIX","url":"https://github.com/CrowCpp/Crow/pull/523"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/crowcpp/crow","events":[{"introduced":"62dae4cc32229e372bb81c0a20c19f2727345e71"},{"fixed":"62dae4cc32229e372bb81c0a20c19f2727345e71"}],"database_specific":{"cpe":"cpe:2.3:a:crowcpp:crow:1.0\\+4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0+4"},{"introduced":"1.0+4"},{"last_affected":"1.0+4"}],"source":["DESCRIPTION","CPE_STRING"]}}],"versions":["1.0+4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38668.json","vanir_signatures_modified":"2026-08-12T13:32:11Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/crowcpp/crow/commit/62dae4cc32229e372bb81c0a20c19f2727345e71","target":{"function":"qs_parse","file":"include/crow/query_string.h"},"deprecated":false,"digest":{"function_hash":"336938383434325191902643563944787926562","length":657},"id":"CVE-2022-38668-6073f16d","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["181069325050730614390994020731278716795","102873384906716306407912897727626310214","88213764132756482993718457627673947381","156651280475791468279827093503004407029","169940499544219386184258702819157697858","159203152154726909533663750365906025093","275499987689425730698452471984301144009","278970894955859571642790026944179829431"],"threshold":0.9},"id":"CVE-2022-38668-cfd24717","signature_type":"Line","signature_version":"v1","source":"https://github.com/crowcpp/crow/commit/62dae4cc32229e372bb81c0a20c19f2727345e71","target":{"file":"include/crow/query_string.h"}}]}}],"schema_version":"1.9.0"}