Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
https://kb.cert.org/vuls/id/461364
https://gitlab.com/hsleisink/hiawatha/-/blame/master/src/http.c?ref_type=heads#L205