Denial of Service in CivetWeb Library
CVE-2025-9648

8.7HIGH

Key Information:

Vendor

Civetweb

Status
Vendor
CVE Published:
29 September 2025

What is CVE-2025-9648?

A vulnerability exists in the CivetWeb library where a flaw in the mg_handle_form_request function can be exploited by remote attackers. By sending a specifically crafted HTTP POST request that includes a null byte in its payload, the server may enter an infinite loop during the parsing of form data. This can lead to a Denial of Service (DoS) condition, causing the server to exhaust its CPU resources and become unresponsive to further requests. The issue is limited to specific versions of the library and has been addressed in a recent commit.

Affected Version(s)

CivetWeb 1.10 <= 1.16

CivetWeb 0 < 1.08

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Artur Łącki
.
CVE-2025-9648 : Denial of Service in CivetWeb Library