Denial-of-Service Vulnerability in facil.io HTTP/1.1 Parser
CVE-2026-66731
Key Information:
Badges
What is CVE-2026-66731?
facil.io versions 0.7.5 and 0.7.6 contain a vulnerability in the HTTP/1.1 chunked transfer encoding parser. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted POST request with a negative chunk size value in the 'Transfer-Encoding: chunked' header. This manipulation leads to the parser calculating an erroneous large positive integer, which corrupts the server's internal state and redirects the read pointer into unmapped memory. Consequently, this results in a server crash, thus impacting service availability.
Affected Version(s)
facil.io 0.7.5 <= 0.7.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
