#VU110697 Integer overflow in FCGI - CVE-2025-40907 

 

#VU110697 Integer overflow in FCGI - CVE-2025-40907

Published: June 10, 2025


Vulnerability identifier: #VU110697
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-40907
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
FCGI
Software vendor:
Catalyst

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to inclusion of code from libfcgi/fcgiapp.c vulnerable to an integer overflow, as described in #VU107896 (CVE-2025-23016). A remote attacker can send a specially crafted request to the application, trigger memory corruption and execute arbitrary code on the system. 


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability. 

External links