{"id":"UBUNTU-CVE-2022-30780","details":"Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.","modified":"2026-04-22T13:21:51.977347Z","published":"2022-06-11T15:15:00Z","upstream":["CVE-2022-30780"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-30780"},{"type":"REPORT","url":"https://podalirius.net/en/cves/2022-30780/"},{"type":"REPORT","url":"https://github.com/p0dalirius/CVE-2022-30780-lighttpd-denial-of-service"},{"type":"REPORT","url":"https://redmine.lighttpd.net/issues/3059"},{"type":"REPORT","url":"https://github.com/lighttpd/lighttpd1.4"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-30780"}],"affected":[{"package":{"name":"lighttpd","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/lighttpd@1.4.35-4ubuntu2.1+esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.35-4ubuntu1","1.4.35-4ubuntu2","1.4.35-4ubuntu2.1","1.4.35-4ubuntu2.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"lighttpd","binary_version":"1.4.35-4ubuntu2.1+esm1"},{"binary_name":"lighttpd-mod-cml","binary_version":"1.4.35-4ubuntu2.1+esm1"},{"binary_name":"lighttpd-mod-magnet","binary_version":"1.4.35-4ubuntu2.1+esm1"},{"binary_version":"1.4.35-4ubuntu2.1+esm1","binary_name":"lighttpd-mod-mysql-vhost"},{"binary_name":"lighttpd-mod-trigger-b4-dl","binary_version":"1.4.35-4ubuntu2.1+esm1"},{"binary_name":"lighttpd-mod-webdav","binary_version":"1.4.35-4ubuntu2.1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-30780.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}