CVE-2025-55763

EUVD-2025-26228
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
civetweb_projectcivetweb
1.14 ≤
𝑥
≤ 1.16
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
civetweb
bookworm
no-dsa
bullseye
postponed
forky
1.16+dfsg-3
fixed
sid
1.16+dfsg-4
fixed
trixie
no-dsa