CVE-2025-9648 describes a denial-of-service vulnerability in the CivetWeb library's mg_handle_form_request function. Remote attackers can trigger an infinite loop and CPU exhaustion by sending a specially crafted HTTP POST request containing a null byte, rendering the service unresponsive. This vulnerability has a CVSS score of 8.7 (HIGH) due to its network attack vector, low attack complexity, and high impact on availability. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, the FAUCET Risk Score of 84/100 indicates significant potential risk. The issue affects only the CivetWeb library and not vendor-pre-built standalone executables.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CivetWeb | CivetWeb | >= 1.10, <= 1.16CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.