HIGH
civetweb
CVE published 2026-08-11
CVE-2026-29035
CVE-2026-29035 is a high-severity heap and stack buffer overflow vulnerability in the read_websocket() function of CivetWeb. This vulnerability allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can exploit this by negotiating permessage-deflate during the WebSocket handshake and sending [truncated]