PatchSiren

civetweb CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH civetweb CVE published 2026-08-11

CVE-2026-29035

CVE-2026-29035 is a high-severity heap and stack buffer overflow vulnerability in the read_websocket() function of CivetWeb. This vulnerability allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Attackers can exploit this by negotiating permessage-deflate during the WebSocket handshake and sending [truncated]