PT-2026-4785 · Unknown · Hiawatha Web Server
Published
2026-01-26
·
Updated
2026-02-18
·
CVE-2025-57783
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hiawatha webserver version 11.7
Description
An issue involving improper header parsing can lead to request smuggling in the Hiawatha webserver. This allows an unauthenticated attacker to potentially access restricted resources managed by the webserver. The issue involves manipulating how the server interprets HTTP headers, potentially allowing an attacker to bypass security checks.
Recommendations
Update Hiawatha webserver to a version that addresses the improper header parsing issue. As a temporary workaround, consider implementing stricter header validation rules to mitigate the risk of request smuggling.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hiawatha Web Server