{
  "threat_severity" : "Moderate",
  "public_date" : "2025-09-29T11:47:56Z",
  "bugzilla" : {
    "description" : "civetweb: Denial of Service in CivetWeb",
    "id" : "2400107",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2400107"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-158",
  "details" : [ "A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By sending a specially crafted HTTP POST request containing a null byte in the payload, the server enters an infinite loop during form data parsing. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests.\nThis issue was fixed in commit 782e189. This issue affects only the library, standalone executable pre-built by vendor is not affected.", "A denial of service flaw has been discovered in CivetWeb. The mg_handle_form_request function allows attackers to trigger a denial of service (DoS) condition by sending a specially crafted HTTP POST request containing a null byte in the payload. The server enters an infinite loop during form data parsing as a result. Multiple malicious requests will result in complete CPU exhaustion and render the service unresponsive to further requests." ],
  "statement" : "On Red Hat systems a denial of service in the CivetWeb application does not pose a broader availability risk to the host.",
  "affected_release" : [ {
    "product_name" : "Red Hat Advanced Cluster Security 4.7",
    "release_date" : "2025-12-16T00:00:00Z",
    "advisory" : "RHSA-2025:23248",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.7::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:sha256:0ba8b652771a517a5c724bc91bbca265a8e86efdd2e83b504c8fb309715a3758"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.8",
    "release_date" : "2025-11-26T00:00:00Z",
    "advisory" : "RHSA-2025:22179",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.8::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:sha256:4e13827b69f9e8be0771e36046c60ec35522b8ab6b93215687fbda51ba928afc"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.9",
    "release_date" : "2025-11-24T00:00:00Z",
    "advisory" : "RHSA-2025:21929",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
    "package" : "advanced-cluster-security/rhacs-collector-rhel8:sha256:59dd5e6cb07cf38e499d909e1c07969db6a750a941051a4f6f7c2fb11ec16cd4"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Not affected",
    "package_name" : "advanced-cluster-security/rhacs-collector-slim-rhel8",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-9648\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-9648\nhttps://cert.pl/en/posts/2025/09/CVE-2025-9648\nhttps://github.com/civetweb/civetweb\nhttps://github.com/civetweb/civetweb/commit/782e18903515f43bafbf2e668994e82bdfa51133\nhttps://github.com/civetweb/civetweb/issues/1348" ],
  "name" : "CVE-2025-9648",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}