Lighttpd
All Lighttpd Resources
|
Blog
Nov 18, 2025
How an Old Bug in Lighttpd Gained New Life in AMI BMC, Including Lenovo and Intel products
The software supply chain is complicated, and all the issues associated with it are something we haven't dealt with before and require a different mindset and approach. The vulnerability in Lighttpd was discovered and fixed back in 2018, but a CVE was not assigned to this vulnerability, and a fix was delivered silently by project maintainers. Frequently, the software that uses the open-sourced components does not consume every single update coming from OSS maintainers and only watches the critical changes or important security fixes to apply. In reality, it's hard to track every change for security issues without specific security advisories and CVE assigned.
Lighttpd
Press
Apr 15, 2024
How to Find Outdated Lighttpd Services
runZero on detecting outdated Lighttpd services in the field.
Lighttpd
Press
Apr 12, 2024
6-Year-Old Bug Will Likely Live Forever in Lenovo, Intel Products
CyberScoop on the permanent nature of the Lighttpd vulnerability.
Lighttpd
Advisory
Apr 11, 2024
[BRLY-2024-004] OOB Read in Lighttpd before 1.4.51
BINARLY team has discovered a Heap Out-of-bounds Read vulnerability in the `lighttpd` web server, allowing a potential attacker to exfiltrate sensitive information from process memory.
Lighttpd
Press
Apr 11, 2024
Intel and Lenovo Servers Impacted by 6-Year-Old BMC Flaw
BleepingComputer reports on long-standing BMC vulnerability in Intel/Lenovo servers.
Lighttpd
Press
Apr 11, 2024
Hackable Intel and Lenovo Hardware That Went Undetected for 5 Years Won't Ever Be Fixed
Ars Technica coverage of unfixable Lighttpd vulnerability in Intel/Lenovo servers.
Lighttpd
Advisory
Apr 11, 2024
[BRLY-2024-003] OOB Read in Lighttpd 1.4.35 used in Lenovo BMC firmware
BINARLY team has discovered a Heap Out-of-bounds Read vulnerability in the web server component of Lenovo BMC firmware, allowing a potential attacker to exfiltrate sensitive information from Lighttpd process memory.
Lighttpd
Advisory
Apr 11, 2024
[BRLY-2024-002] OOB Read in Lighttpd 1.4.45 used in Intel M70KLP series firmware
BINARLY team has discovered a Heap Out-of-bounds Read vulnerability in the web server component of Intel BMC firmware, allowing a potential attacker to exfiltrate sensitive information from Lighttpd process memory.
Lighttpd

Apr 10, 2024
Lighttpd: Silent vulnerability fix exposes Intel and Lenovo servers
Lighttpd
Ship and buy software you can prove is safe.
Schedule a live demo to see how Binarly validates SBOM/CBOM, surfaces risks, and charts a measurable path to post-quantum readiness