{"id":"CVE-2025-55763","details":"Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.","modified":"2026-08-12T15:14:09.822970Z","published":"2025-08-29T00:00:00Z","related":["openSUSE-SU-2026:10818-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55763.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55763.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55763"},{"type":"PACKAGE","url":"https://github.com/civetweb/civetweb"},{"type":"PACKAGE","url":"https://github.com/krispybyte/CVE-2025-55763"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/civetweb/civetweb","events":[{"introduced":"c1d08d3c35bc939da7bec09973bda77c702c1d00"},{"fixed":"d7ba35bbb649209c66e582d5a0244ba988a15159"}],"database_specific":{"cpe":"cpe:2.3:a:civetweb_project:civetweb:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.14"},{"fixed":"1.16"},{"last_affected":"1.16"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v1.15","v1.14"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55763.json","vanir_signatures_modified":"2026-08-12T15:14:09Z","vanir_signatures":[{"source":"https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159","target":{"file":"unittest/public_server.c","function":"START_TEST"},"deprecated":false,"digest":{"length":23217,"function_hash":"236986066512914156358172579350936628310"},"id":"CVE-2025-55763-5eb3e7d7","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2025-55763-d824d1f6","signature_type":"Line","signature_version":"v1","source":"https://github.com/civetweb/civetweb/commit/d7ba35bbb649209c66e582d5a0244ba988a15159","target":{"file":"unittest/public_server.c"},"deprecated":false,"digest":{"line_hashes":["153589748205355842810938074677543536564","64347685013219554478259096366411100607","42582433767714228854703617330205664163","111675856369252008400048137228803108085","275127777792615253363883918877750296299","325948444275312414874240326871799484553"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}