PT-2026-4785 · Unknown · Hiawatha Web Server

Published

2026-01-26

·

Updated

2026-02-18

·

CVE-2025-57783

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hiawatha webserver version 11.7
Description An issue involving improper header parsing can lead to request smuggling in the Hiawatha webserver. This allows an unauthenticated attacker to potentially access restricted resources managed by the webserver. The issue involves manipulating how the server interprets HTTP headers, potentially allowing an attacker to bypass security checks.
Recommendations Update Hiawatha webserver to a version that addresses the improper header parsing issue. As a temporary workaround, consider implementing stricter header validation rules to mitigate the risk of request smuggling.

Fix

Related Identifiers

CVE-2025-57783

Affected Products

Hiawatha Web Server