
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-57783 is an HTTP request smuggling vulnerability caused by improper header parsing in the Hiawatha web server version 11.7. The flaw allows an unauthenticated remote attacker to access restricted resources managed by the Hiawatha web server. It was published on January 26, 2026, and assigned by CERT/CC. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE, CERT/CC).
The root cause is classified as CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling), stemming from improper parsing of HTTP headers in Hiawatha's http.c source file (around line 205). An unauthenticated attacker can craft malformed HTTP requests that are interpreted differently by Hiawatha and any upstream proxy or load balancer, enabling the attacker to smuggle requests past access controls. No authentication or user interaction is required, and the attack is conducted entirely over the network (CERT/CC, GitLab Source).
Successful exploitation allows an unauthenticated attacker to access resources that are otherwise restricted by the Hiawatha web server's access control configuration. The primary impact is a confidentiality breach (low severity per CVSS), with no direct impact on integrity or availability. In environments where Hiawatha fronts sensitive internal applications or acts as a reverse proxy, request smuggling could expose protected endpoints or sensitive data to unauthorized parties (Red Hat CVE, CERT/CC).
As of the available data, there is no confirmed in-the-wild exploitation of CVE-2025-57783, and it does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. No public proof-of-concept exploit code has been identified. The vulnerability requires no privileges or user interaction, lowering the barrier for exploitation if a PoC were to emerge (CERT/CC, Security Online).
Content-Length and Transfer-Encoding headers designed to exploit the improper parsing logic in Hiawatha's http.c.Content-Length and Transfer-Encoding headers present simultaneously; requests to restricted URL paths from unexpected or unauthenticated sources.Users should upgrade Hiawatha to a version beyond 11.7 that addresses the improper header parsing issue; the ENISA advisory notes versions 11.7 and below (≤8.5 in some references) are affected (CERT/CC). As a workaround, deploying a WAF or reverse proxy that strictly normalizes HTTP headers before forwarding to Hiawatha can reduce exposure. Additionally, restricting network access to the Hiawatha server to trusted sources and monitoring access logs for anomalous requests to restricted paths is recommended until a patch is applied (Red Hat CVE).
Security Online reported on the vulnerability as part of a broader article covering flaws in Hiawatha web server, describing it alongside other issues such as authentication bypass and RCE (Security Online). The Hacker News included a brief mention in its weekly security recap (The Hacker News). Overall community reaction has been limited, consistent with the niche deployment footprint of the Hiawatha web server.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."