Junglewise Threat Intelligence

CVE-2026-68005: ACME mini_httpd denial of service via HTTP request header parser

CVE-2026-68005 · Severity: high · CVSS 7.5 · Published 2026-08-17

Executive brief

ACME mini_httpd is a lightweight web server commonly used in embedded devices and IoT appliances. A remote attacker can crash the service by sending specially crafted HTTP requests that cause unbounded memory allocation, exhausting available RAM and triggering a denial of service. The attack requires no authentication and can be executed over the network.

Technical details

The vulnerability exists in the handle_request() function of mini_httpd.c, where the HTTP request header parser allocates memory without any maximum length check. The root cause is a combination of two defects: (1) add_to_buf() calls realloc() repeatedly with no upper limit on header size (industry standard is 8–64 KB, but mini_httpd has no limit), and (2) the alarm(60) timeout is reset on every successful read() call, allowing an attacker to maintain the connection indefinitely by sending at least 1 byte every 60 seconds. An unauthenticated remote attacker can establish multiple concurrent connections and send slow-rate HTTP headers that accumulate unbounded memory until the process is OOM-killed. No patch has been disclosed as of the advisory date.

Affected products

  • ACME Laboratories mini_httpd 1.30 and prior

Timeline

  • 2026-08-17: disclosed

References