Security Advisory

CVE-2026-22903

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-09 07:39:42
Last updated 2026-02-09 15:36:36
Assigner CERTVDE
State PUBLISHED

Description

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.