CVE-2020-25691: UNIX4LYFE Darkhttpd

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.

Affected products

  • UNIX4LYFE Darkhttpd: up to and including 1.13-1

Published 2022-04-01. Last modified 2026-06-17.