CVE-2023-42183: Lockss Classic Lockss Daemon

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.

Affected products

  • Lockss Classic Lockss Daemon: before 1.77.3 (fixed in 1.77.3)

Published 2023-12-15. Last modified 2026-06-17.