Vendor
low
advisory
Denial-of-Service Vulnerability in facil.io HTTP/1.1 Chunked Transfer Encoding Parser (CVE-2026-66731)
1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability exists in facil.io versions 0.7.5 through 0.7.6, allowing attackers to crash the server by sending a POST request with a 'Transfer-Encoding: chunked' header containing a negative chunk size value, which corrupts internal state and leads to a fault.
facil.io 0.7.5 +1
denial-of-service
web-vulnerability
facil.io
1t
1c
low
advisory
CVE-2026-66730 Denial of Service in facil.io Multipart Body Parser
1 TTP 1 CVEA denial-of-service vulnerability exists in facil.io versions 0.6.0 through 0.7.6, specifically in its multipart body parser, allowing an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a malformed multipart/form-data request with a partial closing boundary, effectively disabling the server until manual restart.
facil.io 0.6.0 through 0.7.6
denial-of-service
vulnerability
web-server
1t
1c