Bug 2400107 (CVE-2025-9648) - CVE-2025-9648 civetweb: Denial of Service in CivetWeb
Summary: CVE-2025-9648 civetweb: Denial of Service in CivetWeb
Keywords:
Status: NEW
Alias: CVE-2025-9648
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2400162 2400163 2400164 2400165 2400166
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-29 12:01 UTC by OSIDB Bzimport
Modified: 2025-09-29 17:06 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-09-29 12:01:21 UTC
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests.

This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.


Note You need to log in before you can comment on or make changes to this bug.