CVE-2018-15505: Embedthis Appweb

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.

Affected products

  • Embedthis Appweb: before 7.0.2 (fixed in 7.0.2)
  • Embedthis GoAhead: before 4.0.1 (fixed in 4.0.1)
  • Juniper Junos: version 12.3 only; version 12.3x48 only; version 15.1 only; version 15.1x49 only; version 15.1x53 only; version 16.1 only; …

Published 2018-08-18. Last modified 2026-06-17.