VendorsHiawatha-Webserverhiawathaall versions
Vulnerabilities

Hiawatha-Webserver Hiawatha

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-8358
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
Published 2019-02-16 · Modified
8.1EPSS 0.015
CVE-2025-57783
Improper header parsing may lead to request smuggling
Published 2026-01-26 · Analyzed
5.3EPSS 0.005
CVE-2025-57784
Tomahawk authentication timing attack due to usage of 'strcmp'
Published 2026-01-26 · Analyzed
4.0EPSS 0.002