VYPR
High severity7.5NVD Advisory· Published Jul 27, 2020· Updated Jun 17, 2026

CVE-2020-12845

CVE-2020-12845

Description

Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:cherokee-project:cherokee:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cherokee-project:cherokee:*:*:*:*:*:*:*:*range: >=0.4.27,<=1.2.104
    • (no CPE)range: 0.4.27-1.2.104
  • Cherokee/Cherokeedescription
  • Range: 0.4.27-1.2.104

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.