Security: openwrt/uhttpd
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
uhttpd: leaked client refcount on /ubus/subscribe/ — permanent listener wedgeGHSA-wvgh-cm54-q6f6 published
Aug 3, 2026 by jow-Moderate -
uhttpd: unauthenticated unbounded memory growth — du->url_path leaked on every non-POST /ubus requestGHSA-83vv-qrc6-h3hx published
Aug 3, 2026 by jow-High -
uhttpd: pre-auth HTTP request smuggling (CL.0) — keep-alive connection reused with an unread request bodyGHSA-c2wg-hcff-hqrm published
Aug 3, 2026 by jow-Moderate -
uhttpd: unauthenticated out-of-bounds write via `params` type confusion in POST /ubus/call/GHSA-2mpg-6wp5-435p published
Aug 3, 2026 by jow-High -
uhttpd — pre-auth HTTP header-accumulation memory-exhaustion DoSGHSA-vhx4-3p5q-m59q published
Jul 21, 2026 by jow-High -
HTTP request smuggling via ubus POST body parse-error desyncGHSA-wgwp-64hh-f52p published
Jun 29, 2026 by haukeModerate -
HTTP request smuggling via invalid chunk-length state resetGHSA-p55c-rmhc-qfm5 published
Jun 29, 2026 by haukeHigh -
HTTP request smuggling via case-sensitive Transfer-Encoding matchingGHSA-mcfg-c4r7-pjpf published
Jun 29, 2026 by haukeHigh
Learn more about advisories related to openwrt/uhttpd in the GitHub Advisory Database