🛡️ MGASA-2025-0239 — lighttpd
Description
Updated varnish & lighttpd packages fix security vulnerability
It was discovered that a denial of service attack can be performed on
cache servers that have the HTTP/2 protocol turned on. An attacker can
create a large number of streams and immediately reset them without ever
reaching the maximum number of concurrent streams allowed for the
session, causing the server to consume unnecessary resources processing
requests for which the response will not be delivered (CVE-2025-8671).
Affected software
MGASA-2025-0239 is recorded against 2 packages.
- lighttpd (fixed in 1.4.80-1.3.mga9)
- varnish (fixed in 7.7.3-1.mga9)
Timeline and source
Published on 17 October 2025 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
www.openwall.com (Web)
www.openwall.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| lighttpd | — | 1.4.80-1.3.mga9 |
| varnish | — | 7.7.3-1.mga9 |
References
Similar Threats
- Critical CVE-2025-12642
- Unknown ALPINE-CVE-2025-8671
- Unknown DEBIAN-CVE-2018-25103
- Unknown ALPINE-CVE-2024-3094
- Unknown ALPINE-CVE-2023-44487
More MGASA 2025 advisories
Browse all of MGASA 2025 in the advisory index.
Free Vulnerability Check
Is your site affected by MGASA-2025-0239?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2025-0239 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.