Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29035

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can negotiate permessage-deflate during the WebSocket handshake and send a crafted frame with the RSV1 bit set, causing the server to write a 4-byte zlib sync trailer out-of-bounds past the allocated buffer, leading to heap metadata corruption, denial of service, or potential code execution.

A flaw was found in CivetWeb. An unauthenticated remote attacker could exploit a heap and stack buffer overflow vulnerability by sending specially crafted compressed WebSocket frames. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. The vulnerability occurs during the permessage-deflate decompression process when specific experimental interfaces are enabled.

Отчет

This vulnerability is rated Important because unauthenticated remote attackers can exploit a heap and stack buffer overflow in CivetWeb, potentially leading to denial of service or arbitrary code execution. Exploitation requires the USE_ZLIB and MG_EXPERIMENTAL_INTERFACES features to be enabled, which are not default configurations in Red Hat products.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that CivetWeb is compiled without the USE_ZLIB and MG_EXPERIMENTAL_INTERFACES flags enabled. If CivetWeb is deployed as a library, applications linking against it should avoid enabling these experimental WebSocket features. Disabling these features prevents the vulnerable code path from being active.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2514388CivetWeb: CivetWeb: Arbitrary code execution via crafted WebSocket frames

EPSS

Процентиль: 38%
0.00467
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 дней назад

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can negotiate permessage-deflate during the WebSocket handshake and send a crafted frame with the RSV1 bit set, causing the server to write a 4-byte zlib sync trailer out-of-bounds past the allocated buffer, leading to heap metadata corruption, denial of service, or potential code execution.

CVSS3: 6.5
nvd
7 дней назад

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can negotiate permessage-deflate during the WebSocket handshake and send a crafted frame with the RSV1 bit set, causing the server to write a 4-byte zlib sync trailer out-of-bounds past the allocated buffer, leading to heap metadata corruption, denial of service, or potential code execution.

CVSS3: 6.5
debian
7 дней назад

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ...

CVSS3: 6.5
github
7 дней назад

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can negotiate permessage-deflate during the WebSocket handshake and send a crafted frame with the RSV1 bit set, causing the server to write a 4-byte zlib sync trailer out-of-bounds past the allocated buffer, leading to heap metadata corruption, denial of service, or potential code execution.

EPSS

Процентиль: 38%
0.00467
Низкий

7.5 High

CVSS3