Civetweb Project Civetweb vulnerabilities
5 known vulnerabilities affecting civetweb_project/civetweb.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4
Vulnerabilities
Page 1 of 1
CVE-2020-27304P3CRITICALCVSS 9.8≥ 1.8, < 1.15≥ 1.8, < unspecified2021-10-21
CVE-2020-27304 [CRITICAL] CWE-23 CVE-2020-27304: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windo
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to direct
nvdosv
CVE-2025-9648P3HIGHCVSS 8.7≥ 0, < 1.16+dfsg-2+deb13u1≥ 0, < 1.16+dfsg-42025-09-29
CVE-2025-9648 [HIGH] CVE-2025-9648: A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious reque
osv
CVE-2025-55763P3HIGHCVSS 7.5≥ 1.14, ≤ 1.162025-08-29
CVE-2025-55763 [HIGH] CWE-121 CVE-2025-55763: Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.
nvdosv
CVE-2026-5789P3HIGHCVSS 7.8v1.162026-04-21
CVE-2026-5789 [HIGH] CWE-428 CVE-2026-5789: Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a loca
Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service co
nvd
CVE-2018-12684P4HIGHCVSS 7.1≤ 1.102018-06-22
CVE-2018-12684 [HIGH] CWE-125 CVE-2018-12684: Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attac
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
nvd