Skip to content

krispybyte/CVE-2025-55763

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 

Repository files navigation

CVE-2025-55763

Buffer Overflow in the URI parser of CivetWeb 1.16 (latest release as of yet).

Vulnerable code

The crash occurs here in src/civetweb.c during the last strcat marked.

Fix

See the pull request.

PoC

The PoC crashes the server performing an heap overflow, however it is possible to achieve remote code execution by crafting an exploit for this vulnerability.

cat http_request_crash_input.txt | nc 127.0.0.1 8080

About

Heap overflow PoC for CivetWeb CVE-2025-55763

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors