CRITICAL 9.8 NVD
CVE-2026-51785
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
References
- https://fenrisk.com/hiawatha-http-smuggling
- https://www.rfc-editor.org/rfc/rfc2616
- https://www.rfc-editor.org/rfc/rfc2616.html#section-4.4
- https://www.rfc-editor.org/rfc/rfc9112.html#section-6.3
- https://fenrisk.com/hiawatha-http-smuggling
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-07-31 via NVD.
Risk Timeline
CVE Disclosed2026-07-31 · 3 days ago
Remediation Resources
Analysis & PoC
fenrisk.com/hiawatha-http-smugglingAnalysis & PoC
www.rfc-editor.org/rfc/rfc2616
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.