Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9648

Опубликовано: 29 сент. 2025
Источник: redhat
CVSS3: 5.3

Описание

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

A denial of service flaw has been discovered in CivetWeb. The mg_handle_form_request function allows attackers to trigger a denial of service (DoS) condition by sending a specially crafted HTTP POST request containing a null byte in the payload. The server enters an infinite loop during form data parsing as a result. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests.

Отчет

On Red Hat systems a denial of service in the CivetWeb application does not pose a broader availability risk to the host.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-collector-slim-rhel8Not affected
Red Hat Advanced Cluster Security 4.7advanced-cluster-security/rhacs-collector-rhel8FixedRHSA-2025:2324816.12.2025
Red Hat Advanced Cluster Security 4.8advanced-cluster-security/rhacs-collector-rhel8FixedRHSA-2025:2217926.11.2025
Red Hat Advanced Cluster Security 4.9advanced-cluster-security/rhacs-collector-rhel8FixedRHSA-2025:2192924.11.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-158
https://bugzilla.redhat.com/show_bug.cgi?id=2400107civetweb: Denial of Service in CivetWeb

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
6 месяцев назад

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

nvd
6 месяцев назад

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

msrc
6 месяцев назад

Denial of Service in CivetWeb

debian
6 месяцев назад

A vulnerability in the CivetWeb library's function mg_handle_form_requ ...

github
6 месяцев назад

A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests. This issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.

5.3 Medium

CVSS3