CVE-2018-25103

Use-after-free vulnerabilities in lighttpd <= 1.4.50

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.


We have discovered 55,224 live websites that are affected by CVE-2018-25103.

Test my site




Affected Software

Product  lighttpd
Category Web Servers
Vulnerable Domains55,224 live websites (87.20% of lighttpd install base)
Vulnerable Versions
  • from 0 through 1.4.50
Vulnerable Versions Count35 versions ( 57.38% of all versions)



Details

  • Published - Jun 17, 2024
  • Updated - Feb 13, 2025

Credits

  • Thanks to VDOO Embedded Security part of JFROG for reporting the vulnerability in the If-Modified-Since header with line folding, and thanks to Marcus Wengelin for reporting the vulnerability in the Range header with a specially crafted pair of Range headers. (finder)

CVE-2018-25103 usage by Country

United States887 websites



Russia48,441 websites
Germany2,008 websites
France1,016 websites
Czech Republic365 websites
Singapore279 websites
New Zealand240 websites
Australia173 websites
China145 websites
Poland138 websites

CVE-2018-25103 usage by TLD

.ru45,010 websites
.com1,675 websites
.de1,570 websites
.net632 websites
.fr520 websites
.org355 websites
.cz235 websites
.pl114 websites
.ch101 websites
.eu97 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-25103

Top websites that are affected by CVE-2018-25103. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.**.th Thailand**,***
**********.com United States**,***
***.*****.fi Sweden**,***
*********.****.cz Czech Republic**,***
*******.ru Russia**,***
*****.to United States**,***
****.ru Russia**,***
************.pe Peru***,***
********.is Singapore***,***
*******.********.com United States***,***
See full domain list

FAQ

A total of 55,224 websites have been identified as vulnerable to CVE-2018-25103, discovered through global website indexing conducted by WebTechSurvey.
lighttpd is susceptible to CVE-2018-25103 vulnerability.
lighttpd versions before, and including, 1.4.50 are vulnerable to CVE-2018-25103.