VYPR

facil.io

by Facil.io

CVEs (3)

  • CVE-2026-66731HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a…

  • CVE-2026-66730HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The…

  • CVE-2026-66729HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a…