CVE-2024-22087: Alekseykurepin Pico HTTP Server In C

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.

Affected products

Published 2024-01-05. Last modified 2026-06-17.