{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/facil.io--0.7.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-66729"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["facil.io (\u003c= 0.7.6)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","web-server"],"_cs_type":"advisory","_cs_vendors":["boazsegev"],"content_html":"\u003cp\u003eCVE-2026-66729 describes an integer underflow vulnerability identified in \u003ccode\u003efacil.io\u003c/code\u003e versions up to and including 0.7.6. This flaw resides within the multipart MIME body parser, specifically in \u003ccode\u003ehttp_mime_parser.h\u003c/code\u003e. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted HTTP POST request. The attack involves manipulating the \u003ccode\u003eContent-Disposition\u003c/code\u003e header by providing an empty field name, which triggers a \u003ccode\u003euint32_t\u003c/code\u003e wraparound. This leads to an out-of-bounds memory read beyond the expected \u003ccode\u003ename\u003c/code\u003e pointer, culminating in a bus fault that crashes the server's handling worker. The vulnerability requires only a single POST request to cause a Denial of Service, making affected \u003ccode\u003efacil.io\u003c/code\u003e deployments susceptible to easy disruption.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker identifies a server running \u003ccode\u003efacil.io\u003c/code\u003e through version 0.7.6.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting the vulnerable server.\u003c/li\u003e\n\u003cli\u003eThe crafted POST request includes a \u003ccode\u003eContent-Disposition\u003c/code\u003e header containing a multipart form-data structure.\u003c/li\u003e\n\u003cli\u003eWithin this \u003ccode\u003eContent-Disposition\u003c/code\u003e header, the attacker sets a field name attribute (e.g., \u003ccode\u003ename\u003c/code\u003e or \u003ccode\u003efilename\u003c/code\u003e) to an empty string.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003efacil.io\u003c/code\u003e application's multipart MIME body parser (implemented in \u003ccode\u003ehttp_mime_parser.h\u003c/code\u003e) attempts to process the malformed \u003ccode\u003eContent-Disposition\u003c/code\u003e header.\u003c/li\u003e\n\u003cli\u003eDuring parsing, the empty field name triggers an integer underflow, causing a \u003ccode\u003euint32_t\u003c/code\u003e variable to wrap around.\u003c/li\u003e\n\u003cli\u003eThis wraparound condition leads to an out-of-bounds memory read past the \u003ccode\u003ename\u003c/code\u003e pointer.\u003c/li\u003e\n\u003cli\u003eThe out-of-bounds memory access results in a bus fault, causing the \u003ccode\u003efacil.io\u003c/code\u003e handling worker process to crash and the server to experience a Denial of Service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66729 leads directly to a Denial of Service (DoS) condition on affected servers. Attackers can remotely crash the server process with a single HTTP POST request, making the server unresponsive and unavailable to legitimate users. While specific victim numbers or targeted sectors are not detailed, any organization utilizing \u003ccode\u003efacil.io\u003c/code\u003e through version 0.7.6 in an internet-facing capacity is vulnerable to service disruption. This could impact critical web services, APIs, or other applications built upon the \u003ccode\u003efacil.io\u003c/code\u003e framework.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66729 immediately by upgrading \u003ccode\u003efacil.io\u003c/code\u003e to a version beyond 0.7.6 or applying the provided security fix.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for \u003ccode\u003ePOST\u003c/code\u003e requests containing unusual or malformed \u003ccode\u003eContent-Disposition\u003c/code\u003e headers, particularly those with empty \u003ccode\u003ename\u003c/code\u003e or \u003ccode\u003efilename\u003c/code\u003e attributes, as indicated by the vulnerability description for CVE-2026-66729.\u003c/li\u003e\n\u003cli\u003eReview the references from the NVD entry to understand the full technical details of CVE-2026-66729 and any potential workarounds.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T17:18:04Z","date_published":"2026-07-27T17:18:04Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66729/","summary":"An integer underflow vulnerability in facil.io through version 0.7.6 allows unauthenticated remote attackers to crash the server process via a crafted Content-Disposition header with an empty field name, leading to a Denial of Service.","title":"CVE-2026-66729: facil.io Integer Underflow Vulnerability Leading to Server Crash","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66729/"}],"language":"en","title":"CraftedSignal Threat Feed - Facil.io (\u003c= 0.7.6)","version":"https://jsonfeed.org/version/1.1"}