Denial-of-Service Vulnerability in facil.io by Facil
CVE-2026-66730
Key Information:
Badges
What is CVE-2026-66730?
The facil.io framework versions 0.6.0 to 0.7.6 contain a vulnerability in the multipart body parser that can lead to a denial-of-service condition. An unauthenticated remote attacker can exploit this flaw by sending specially crafted multipart/form-data requests with a partial closing boundary. This causes the parser to loop indefinitely without consuming data, which results in all worker processes reaching 100% CPU utilization. Consequently, the affected server may become unresponsive and require a manual restart to restore functionality.
Affected Version(s)
facil.io 0.6.0 <= 0.7.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
