CVE-2025-57783: Hiawatha-Webserver Hiawatha
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
Affected products
- Hiawatha-Webserver Hiawatha: version 11.7 only
Published 2026-01-26. Last modified 2026-06-17.