What is CVE-2026-29035?
A heap and stack buffer overflow vulnerability exists in CivetWeb's read_websocket() function. This allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are defined. Affected systems should be updated immediately.
Azərbaycanca: CivetWeb-in read_websocket() funksiyasında heap və stack buffer overflow zəifliyi aşkarlanıb. Bu, USE_ZLIB və MG_EXPERIMENTAL_INTERFACES aktiv olduqda sıxılmış WebSocket kadrları göndərən uzaqdan autentifikasiya olunmamış hücumçulara yaddaşı korlamağa imkan verir. Təsirlənən sistemlərdə dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What configuration options must be enabled to successfully exploit CVE-2026-29035 in CivetWeb?
Both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES must be defined for the exploit to succeed.
Which function in CivetWeb is affected by CVE-2026-29035?
The vulnerability specifically resides in the read_websocket() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.