CVE-2023-26104: Lite-Web-Server Project Lite-Web-Server
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Affected products
- Lite-Web-Server Project Lite-Web-Server: affected versions not specified
Published 2023-02-25. Last modified 2026-06-17.