USN-8749-1: CivetWeb vulnerabilities
Ubuntu USN-8749-1 patches CivetWeb URI and HTTP request parsing flaws enabling remote DoS or possible code execution.
Ubuntu Security Notice USN-8749-1 addresses two CivetWeb vulnerabilities. CVE-2025-55763 involves incorrect URI parsing that could allow a remote attacker to cause denial of service or execute arbitrary code, affecting Ubuntu 22.04 LTS and 24.04 LTS. CVE-2025-9648 involves incorrect HTTP request parsing enabling remote denial of service.
- CVE-2025-55763: remote attacker could execute code via crafted URI parsing
- CVE-2025-9648: remote denial of service via crafted HTTP requests
- Only Ubuntu 22.04 LTS and 24.04 LTS affected by CVE-2025-55763
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-55763 | Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2025-9648 | A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected. NVD description · AI analysis pending | 8.7 | <1% | — | — |
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763) It was discovered that CivetWeb did not correctly handle parsing certain HTTP requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2025-9648)
This source does not provide full text. Read it at ubuntu.com.