VYPR

Infinite-Loop-DoS-in-facil.io-MIME-Parser

by Theopaid

CVEs (1)

  • CVE-2026-66730Jul 27, 2026
    risk 0.00cvss epss 0.01

    facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The…