PatchSiren

Zervit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Zervit CVE published 2026-04-21

CVE-2025-13826

A remote denial-of-service vulnerability exists in Zervit's portable HTTP/web server. The flaw stems from insufficient validation of user-supplied input during configuration reset requests. An unauthenticated attacker can exploit this by sending malicious requests to trigger a DoS condition, requiring manual application restart to restore service. The vulnerability was published on 2026-04-21 and last mod [truncated]