VDB
CVE-2025-57783
CVE-2025-57783
PUBLISHED
CVSS 8.600000381469727 HIGH
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
EPSS 0.01% · 2.0th percentile
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.01%
2.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hiawatha-webserver | hiawatha | 11.7, 11.7 |
| Hiawatha | Hiawatha Web server | 11.7, 11.7 |
Timeline
- Sep 9, 2025 PoC Published
- Jan 26, 2026 CVE Published
- Jan 27, 2026 EPSS Score
- Jan 30, 2026 EPSS Score
- Feb 1, 2026 EPSS Score
- Feb 4, 2026 EPSS Score
- Feb 6, 2026 EPSS Score
- Feb 9, 2026 EPSS Score
- Feb 11, 2026 EPSS Score
- Feb 14, 2026 EPSS Score
- Feb 16, 2026 EPSS Score
- Feb 18, 2026 CVE Updated