CVE-2015-1548: Acme Mini Httpd

Medium severity, CVSS 5.0. EPSS: 1.6% chance of exploitation in the next 30 days.

mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.

Affected products

  • Acme Mini Httpd: up to and including 1.21

Published 2015-02-10. Last modified 2026-06-17.