{"id":"CVE-2025-12642","details":"lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks.\n\nSuccessful exploitation may allow an attacker to:\n\n  *  Bypass access control rules\n  *  Inject unsafe input into backend logic that trusts request headers\n  *  Execute HTTP Request Smuggling attacks under some conditions\n\n\nThis issue affects lighttpd1.4.80","modified":"2026-07-15T06:01:37.145871Z","published":"2025-11-03T20:17:06.410Z","references":[{"type":"FIX","url":"https://github.com/lighttpd/lighttpd1.4/commit/35cb89c103877de62d6b63d0804255475d77e5e1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lighttpd/lighttpd1.4","events":[{"introduced":"b2bdd270506b4cad6a571b629e4fa0a01cd24631"},{"last_affected":"b2bdd270506b4cad6a571b629e4fa0a01cd24631"},{"fixed":"35cb89c103877de62d6b63d0804255475d77e5e1"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:lighttpd:lighttpd:1.4.80:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.4.80"},{"last_affected":"1.4.80"}]}}],"versions":["1.4.80","lighttpd-1.4.80"],"database_specific":{"vanir_signatures_modified":"2026-07-15T06:01:37Z","vanir_signatures":[{"digest":{"line_hashes":["177279775846748800587473156359973412692","234107947651447384615462498936120486077","302025777481488930004506134913590170429","53861381006875801283685841489596921050"],"threshold":0.9},"id":"CVE-2025-12642-473a78bc","signature_type":"Line","signature_version":"v1","source":"https://github.com/lighttpd/lighttpd1.4/commit/35cb89c103877de62d6b63d0804255475d77e5e1","target":{"file":"src/request.c"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12642.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}