Incorrect input validation on the Zervit portable HTTP/Web server

Posted date 21/04/2026
Identificador
INCIBE-2026-298
Importance
4 - High
Affected Resources

Zervit

Description

INCIBE has coordinated the publication of a high-severity vulnerability affecting Zervit, a portable HTTP/web server.  The vulnerability was discovered by Rafael Pedrero.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:

  • CVE-2025-13826: CVSS v4.0: 8.2 | CVSS AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/V:D/RE:L | CWE-20
Solution

There is no solution reported at this time.

Detail

CVE-2025-13826: Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inadequate validation of user-supplied input. An attacker can exploit this vulnerability by sending malicious requests. If the vulnerability is successfully exploited, the application can be made to stop responding, resulting in a DoS condition. It is possible to manually restart the application.

CVE
Explotación
No
CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2025-13826 Alta No Zervit
References list