CVE-2018-15505

HIGH

Embedthis Appweb < 7.0.2 and GoAhead < 4.0.1 - Denial of Service via Malformed IPv6 Host Header

Title source: llm
STIX 2.1

Description

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.

References (4)

Core 4

Scores

CVSS v3 7.5
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (5)
embedthis/appweb < 7.0.2
embedthis/goahead < 4.0.1
juniper/junos 12.3 (17 CPE variants)
juniper/junos 12.3x48 (17 CPE variants)
juniper/junos 15.1 (14 CPE variants)
Published Aug 18, 2018
Tracked Since Feb 18, 2026