In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Conclusion & alert: CVE-2022-37797 is rated High Exploit Risk (72.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.91%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.44% | 1.91% | +0.47% |
| 2 | 2026-03-24 | 0.36% | 1.44% | +1.09% |
| 3 | 2026-01-13 | — | 0.36% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-37797 not yet assigned priority: Debian including 1 source packages (lighttpd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2022-37797 |
gentoo
|
low | CVE-2022-37797: 1 GLSA(s) (202210-12), 1 atom(s) (www-servers/lighttpd); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2022-37797 |
suse
|
high | CVE-2022-37797 severity important: SUSE including 40 source package names (lighttpd, lighttpd-1.4.66-1.1, …), 69 product×package rows across 9 product lines (SUSE Linux Enterprise High Availability Extension 12 SP4, SUSE Linux Enterprise High Availability Extension 12 SP5, … (9 product lines)): Fixed 65, Known Not Affected 4. | https://www.suse.com/security/cve/CVE-2022-37797/ |
ubuntu
|
medium | CVE-2022-37797 medium priority: Ubuntu including 1 source packages (lighttpd), 13 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 8, ignored 2, needed 2, released 1. | https://ubuntu.com/security/CVE-2022-37797 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lighttpd | lighttpd | 1.4.65 | cpe:2.3:a:lighttpd:lighttpd:1.4.65:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2022/10/msg00002.html | Mailing List Third Party Advisory |
| https://redmine.lighttpd.net/issues/3165 | Exploit Issue Tracking Third Party Advisory |
| https://security.gentoo.org/glsa/202210-12 | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5243 | Mailing List Third Party Advisory |