CVE-2016-9564: Boa

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.

Affected products

  • Boa Boa: version 0.92r only

Published 2016-11-30. Last modified 2026-06-17.