Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hiawatha.leisink
Hiawatha.leisink hiawatha Webserver |
|
| Weaknesses | CWE-415 | |
| CPEs | cpe:2.3:a:hiawatha.leisink:hiawatha_webserver:11.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Hiawatha.leisink
Hiawatha.leisink hiawatha Webserver |
Tue, 27 Jan 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hiawatha
Hiawatha web Server |
|
| Vendors & Products |
Hiawatha
Hiawatha web Server |
Mon, 26 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 26 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution. | |
| Title | Double free in XSLT in 'show_index' | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-01-26T20:54:04.714Z
Reserved: 2025-08-19T17:36:13.586Z
Link: CVE-2025-57785
Updated: 2026-01-26T20:53:52.643Z
Status : Analyzed
Published: 2026-01-26T18:16:27.570
Modified: 2026-02-13T15:21:40.900
Link: CVE-2025-57785
No data.
OpenCVE Enrichment
Updated: 2026-01-27T09:03:18Z