Releases5
Frequency1 year 1 month
Last Release
Stars1.27K
When you need a web server in a hurry.

CVE History

CVEPublishedCVSS v3CVSS v2
5.5 MEDIUM

darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

9.8 CRITICAL

darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.