VYPR

Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash

by Theopaid

CVEs (1)

  • CVE-2026-66729HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a…