Junglewise Threat Intelligence

CVE-2025-13826: Zervit portable HTTP server denial of service via configuration reset

CVE-2025-13826 · Severity: info · CVSS 8.2 · Published 2026-04-21

Executive brief

Zervit, a portable web server used for hosting content, is vulnerable to a flaw that allows remote attackers to crash the service. By sending a specifically crafted configuration reset request, an attacker can cause the server to stop responding to legitimate users. While the server can be manually restarted to restore operations, the attack can lead to significant service downtime and disruption of web-based activities.

Technical details

A denial-of-service (DoS) vulnerability exists in the Zervit portable HTTP/web server due to improper input validation (CWE-20). The flaw is triggered when the server processes a configuration reset request containing malicious user-supplied input. An unauthenticated remote attacker can exploit this by sending a specially crafted network request to the server. Successful exploitation causes the application to hang or stop responding, necessitating a manual restart to recover. As of the advisory date, no official patch or solution has been reported.

Affected products

  • Zervit Zervit portable HTTP/web server

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory

References