VDB

CVE-2025-57783

CVE-2025-57783 PUBLISHED CVSS 8.600000381469727 HIGH

Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.

EPSS 0.01% · 2.0th percentile

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.01%
2.0th percentile

Affected Products

VendorProductVersions
hiawatha-webserverhiawatha11.7, 11.7
HiawathaHiawatha Web server11.7, 11.7

Timeline

  • Sep 9, 2025 PoC Published
  • Jan 26, 2026 CVE Published
  • Jan 27, 2026 EPSS Score
  • Jan 30, 2026 EPSS Score
  • Feb 1, 2026 EPSS Score
  • Feb 4, 2026 EPSS Score
  • Feb 6, 2026 EPSS Score
  • Feb 9, 2026 EPSS Score
  • Feb 11, 2026 EPSS Score
  • Feb 14, 2026 EPSS Score
  • Feb 16, 2026 EPSS Score
  • Feb 18, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›