CVE-2020-15689: Embedthis Appweb

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.

Affected products

  • Embedthis Appweb: before 7.2.2 (fixed in 7.2.2); from 8.0.0, before 8.1.0 (fixed in 8.1.0)

Published 2020-07-13. Last modified 2026-06-17.