Skip to content
Ubuntu CivetWeb Important Denial Of Service Risks USN-8749

Ubuntu CivetWeb Important Denial Of Service Risks USN-8749

Linuxsecurity LinuxSecurity Advisories September 14, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Several security issues were fixed in CivetWeb. Software Description: - civetweb: Embeddable web server with optional CGI, SSL and Lua support Details: It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763) It was discovered that CivetWeb did not correctly handle parsing certain HTTP requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2025-9648)

Several security issues were fixed in CivetWeb.

Software Description:

- civetweb: Embeddable web server with optional CGI, SSL and Lua support

It was discovered that CivetWeb did not correctly handle parsing certain

URIs. A remote attacker could possibly use this issue to cause a denial

of service or execute arbitrary code. This issue only affected

Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763)

It was discovered that CivetWeb did not correctly handle parsing certain

HTTP requests. A remote attacker could possibly use this issue to cause

a denial of service. (CVE-2025-9648)

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS civetweb 1.16+dfsg-3ubuntu0.1 libcivetweb-dev 1.16+dfsg-3ubuntu0.1 libcivetweb1 1.16+dfsg-3ubuntu0.1 Ubuntu 24.04 LTS civetweb 1.16+dfsg-1ubuntu0.1 libcivetweb-dev 1.16+dfsg-1ubuntu0.1 libcivetweb1 1.16+dfsg-1ubuntu0.1 Ubuntu 22.04 LTS civetweb 1.15+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libcivetweb-dev 1.15+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro libcivetweb1 1.15+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart civetweb to make all the necessary changes.

CVE-2025-55763, CVE-2025-9648

Ubuntu Security Notice USN-8749-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Platforms (1)