CVE-2025-55763

Source
https://cve.org/CVERecord?id=CVE-2025-55763
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55763.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55763
Downstream
Related
Published
2025-08-29T00:00:00Z
Modified
2026-08-12T15:14:09.822970Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55763.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/civetweb/civetweb

Affected ranges

Type
GIT
Repo
https://github.com/civetweb/civetweb
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:civetweb_project:civetweb:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.14"
        },
        {
            "fixed": "1.16"
        },
        {
            "last_affected": "1.16"
        }
    ],
    "source": [
        "DESCRIPTION",
        "CPE_RANGE"
    ]
}

Affected versions

v1.*
v1.14
v1.15

Database specific

vanir_signatures_modified
"2026-08-12T15:14:09Z"
vanir_signatures
[
    {
        "id": "CVE-2025-55763-5eb3e7d7",
        "deprecated": false,
        "signature_type": "Function",
        "signature_version": "v1",
        "digest": {
            "length": 23217.0,
            "function_hash": "236986066512914156358172579350936628310"
        },
        "source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
        "target": {
            "function": "START_TEST",
            "file": "unittest/public_server.c"
        }
    },
    {
        "id": "CVE-2025-55763-d824d1f6",
        "deprecated": false,
        "signature_type": "Line",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "153589748205355842810938074677543536564",
                "64347685013219554478259096366411100607",
                "42582433767714228854703617330205664163",
                "111675856369252008400048137228803108085",
                "275127777792615253363883918877750296299",
                "325948444275312414874240326871799484553"
            ]
        },
        "source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
        "target": {
            "file": "unittest/public_server.c"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55763.json"