CVE-2020-13432: Rejetto HTTP File Server

High severity, CVSS 7.5. EPSS: 30.9% chance of exploitation in the next 30 days.

rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.

Affected products

  • Rejetto HTTP File Server: version 2.3m only

Published 2020-06-08. Last modified 2026-06-17.