Lighttpd 1.4.73 Released: Elimination of DOS-Vulnerability in HTTP/2

LightTPD Releases 1.4.73 Version

The latest version of LightTPD, a high-performance web server software, has been released. This new version aims to combine high performance, safety, compliance with standards, and flexibility of configuration. LightTPD is known for its suitability for use on highly loaded systems, with a focus on low CPU memory and resources. The project code is written in the language of SI and spreads under the BSD license.

One of the key updates in the new version is the addition of measures to address the class of DoS attacks called “Rapid Reset.” These attacks involve creating a large number of immediately discharged flows within a single HTTP/2 connection. To protect against such attacks and accelerate the analysis of HTTP/2 header flags, Mod_H2 has introduced changes. In cases of abnormally large numbers of incoming queries, the server now responds with a “Goaway” message.

In addition to the security enhancements, the latest version of LightTPD also introduces a new MIME-type, “.MKV”. This update allows the server to handle MKV (Matroska) files more efficiently, contributing to enhanced multimedia support.


GitHub Repository

More information about the release can be found here.

/Reports, release notes, official announcements.