VYPR

Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash

by Theopaid

CVEs (1)

  • CVE-2026-66729Jul 27, 2026
    risk 0.00cvss epss 0.01

    facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a…