Denial of Service in CivetWeb Library
CVE-2025-9648
What is CVE-2025-9648?
A vulnerability exists in the CivetWeb library where a flaw in the mg_handle_form_request function can be exploited by remote attackers. By sending a specifically crafted HTTP POST request that includes a null byte in its payload, the server may enter an infinite loop during the parsing of form data. This can lead to a Denial of Service (DoS) condition, causing the server to exhaust its CPU resources and become unresponsive to further requests. The issue is limited to specific versions of the library and has been addressed in a recent commit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CivetWeb 1.10 <= 1.16
CivetWeb 0 < 1.08
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
