CVE-2026-66729
Last modified
CVE-2026-66729 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| boazsegev | facil.io | >= 0.6.0, <= 0.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66729?
How severe is CVE-2026-66729?
How do I fix CVE-2026-66729?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66712Unauthenticated Broken Access Control in Simple Membership <…7.5
- CVE-2026-66713Deserialization of Untrusted Data (CWE-502) in the Tribes-ba…9.8
- CVE-2026-6672The Affiliate Program Suite — SliceWP Affiliates plugin for …6.4
- CVE-2026-66720The GOOSE subscriber component improperly validates the UTC …7.1
- CVE-2026-66723MWDB Core versions >=2.2.0 and <2.19.0 contain a missing aut…7
- CVE-2026-66724MWDB Core versions >=2.0.0 and <2.19.0 contain a missing aut…5.3
- CVE-2026-6673Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5…6.4
- CVE-2026-66730facil.io 0.6.0 through 0.7.6 contains a denial-of-service vu…8.7
- CVE-2026-66731facil.io 0.7.5 through 0.7.6 contains a denial-of-service vu…8.7
- CVE-2026-66732Sonic 3 A.I.R. before commit 2492d18 contains a missing sour…8.3
- CVE-2026-66733Sonic 3 A.I.R. before commit 2492d18 contains an unbounded m…8.7
- CVE-2026-66737Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-66729?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
