Vendor
low
advisory
CVE-2026-66729: facil.io Integer Underflow Vulnerability Leading to Server Crash
1 TTP 1 CVEAn integer underflow vulnerability in facil.io through version 0.7.6 allows unauthenticated remote attackers to crash the server process via a crafted Content-Disposition header with an empty field name, leading to a Denial of Service.
facil.io
denial-of-service
vulnerability
web-server
1t
1c
high
threat
Improper Input Validation in boazsegev facil.io WebSocket Frame Parser (CVE-2026-16632)
1 TTP 1 CVEA high-severity improper input validation vulnerability, CVE-2026-16632, exists in the `websocket_on_protocol_error` function of the `boazsegev facil.io` WebSocket Frame Parser, allowing a remote unauthenticated attacker to manipulate the `on_message` argument with a publicly available exploit, potentially leading to denial of service or information disclosure.
exploited
facil.io 0.7.4 +4
vulnerability
web-application
input-validation
remote-code-execution
1t
1c