CVE-2024-22087: Alekseykurepin Pico HTTP Server In C
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.
Affected products
- Alekseykurepin Pico HTTP Server In C: up to and including 2021-04-02
Published 2024-01-05. Last modified 2026-06-17.