Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55763.json",
"cna_assigner": "mitre"
}"2026-08-12T15:14:09Z"
[
{
"id": "CVE-2025-55763-5eb3e7d7",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 23217.0,
"function_hash": "236986066512914156358172579350936628310"
},
"source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
"target": {
"function": "START_TEST",
"file": "unittest/public_server.c"
}
},
{
"id": "CVE-2025-55763-d824d1f6",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"153589748205355842810938074677543536564",
"64347685013219554478259096366411100607",
"42582433767714228854703617330205664163",
"111675856369252008400048137228803108085",
"275127777792615253363883918877750296299",
"325948444275312414874240326871799484553"
]
},
"source": "https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159",
"target": {
"file": "unittest/public_server.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55763.json"