CVE-2024-23771: UNIX4LYFE Darkhttpd
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
Affected products
- UNIX4LYFE Darkhttpd: before 1.15 (fixed in 1.15)
Published 2024-01-22. Last modified 2026-06-17.