CVE-2025-55763

HIGH

CivetWeb <1.17 - Buffer Overflow

Title source: llm

Description

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

Exploits (1)

nomisec WORKING POC 3 stars
by krispybyte · poc
https://github.com/krispybyte/CVE-2025-55763

Scores

CVSS v3 7.5
EPSS 0.0463
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-121
Status published
Products (1)
civetweb_project/civetweb 1.14 - 1.16
Published Aug 29, 2025
Tracked Since Feb 18, 2026