Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55763.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55763.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "236986066512914156358172579350936628310",
"length": 23217
},
"id": "CVE-2025-55763-5eb3e7d7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
"target": {
"file": "unittest/public_server.c",
"function": "START_TEST"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"153589748205355842810938074677543536564",
"64347685013219554478259096366411100607",
"42582433767714228854703617330205664163",
"111675856369252008400048137228803108085",
"275127777792615253363883918877750296299",
"325948444275312414874240326871799484553"
],
"threshold": 0.9
},
"id": "CVE-2025-55763-d824d1f6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
"target": {
"file": "unittest/public_server.c"
}
}
]
"2026-08-12T15:14:09Z"