Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.775
EPSS Ranking 98.9%