Loading
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.
Use CWE-787, Embedthis vendor hub and Goahead product page to widen CVE-2019-19240 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-41615, CVE-2021-43298 and CVE-2021-42342 for nearby disclosures in the same product family.