Back

HIGH

Denial of Service in CivetWeb

Published Sep 29, 2025

Description

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests.

This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

Affected products

Remediation

Red Hat statement

On Red Hat systems a denial of service in the CivetWeb application does not pose a broader availability risk to the host.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CERT-PL
Published Sep 29, 2025
Updated Sep 29, 2025
Reserved Aug 29, 2025

CISA Vulnrichment

Updated Sep 29, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Sep 29, 2025
Bugzilla 2400107

ENISA EUVD

Assigner CERT-PL
Published Sep 29, 2025
Updated Sep 29, 2025

GitHub

No data