9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.
AI Analysis
Stack buffer overflow in lighttpd via overly long SESSIONID cookie, potentially enabling remote code execution
Basic Information
ID
CVE-2026-22903
Source
CERTVDE
Published
Feb 9, 2026 at 07:39
Affected Product
Vendor
WAGO
Product
lighttpd
Version
0.0.0, 2.64
Affected Versions
WAGO 0852-1322 0.0.0
WAGO 0852-1328 0.0.0
WAGO 0852-1322 2.64
WAGO 0852-1328 2.64
WAGO 0852-1328 0.0.0
WAGO 0852-1322 2.64
WAGO 0852-1328 2.64
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
WAGO
Product
lighttpd
Version
0.0.0, 2.64