CVE-2025-57783

Source
https://cve.org/CVERecord?id=CVE-2025-57783
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57783.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57783
Published
2026-01-26T17:45:36.947Z
Modified
2026-07-15T01:49:17.354220170Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Improper header parsing may lead to request smuggling
Details

Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.

Database specific
{
    "cna_assigner": "certcc",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57783.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "11.7"
                },
                {
                    "last_affected": "8.5"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / gitlab.com/hsleisink/hiawatha

Affected ranges

Type
GIT
Repo
https://gitlab.com/hsleisink/hiawatha
Events
Database specific
{
    "cpe": "cpe:2.3:a:hiawatha-webserver:hiawatha:11.7:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "11.7"
        },
        {
            "last_affected": "11.7"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

11.*
11.7
v11.*
v11.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57783.json"