CVE-2026-22903Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-09); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-09: 3Mentions · 2026-02-10: 2Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 202-0902-10
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-093
Disclosure3
2026-02-102
Patch2
Full discourse5 posts
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The advisory highlights three critical CVEs, provides technical details and CVSS scores, and focuses on patching/updating affected components along with mitigation steps, without indicating active exploitation or a PoC.

    00010105
    64 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22903 - Critical An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, ca... https://www.thehackerwire.com/vulnerability/CVE-2026-22903/ https://t.co/q58KqdRdfI

    Post summary

    The post discloses a stack buffer overflow in a modified lighttpd server triggered by an overly long SESSIONID cookie, with no PoC, exploit code, or patch information provided.

    00010117
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22903 An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modifie… https://www.cve.org/CVERecord?id=CVE-2026-22903

    Post summary

    The text describes CVE‑2026‑22903, noting that an unauthenticated remote attacker can trigger a stack buffer overflow by sending an overly long SESSIONID cookie; it does not provide a PoC, patch, or evidence of active exploitation.

    00010209
    56.5K followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces critical CVEs with detailed technical descriptions and provides specific patch versions and mitigations, focusing on remediation rather than exploitation evidence.

    0000080
    64 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22903: CRITICAL] Vulnerability alert: A crafted HTTP request can cause a stack buffer overflow in lighttpd, leading to a crash and possible remote code execution. Stay cyber safe!#cve,CVE-2026-22903,#cybersecurity https://cvefind.com/CVE-2026-22903

    Post summary

    The post alerts that CVE‑2026‑22903 is a critical stack buffer overflow in lighttpd, potentially enabling remote code execution via crafted HTTP requests.

    0000065
    583 followersView on X

Explore more