facil.io 0.7.6 及之前版本在 multipart MIME 体解析器中存在整数下溢漏洞,允许未经身份验证的远程攻击者通过发送包含空字段名的构造的 Content-Disposition 头信息来导致服务器进程崩溃。攻击者可触发 http_mime_parser.h 中的 uint32_t 整数回绕(wraparound),导致在名称指针之后发生越界内存读取,从而引发总线错误(bus fault),使得处理该请求的工作线程在接收到单个 POST 请求后崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-66730 | 7.5 HIGH | facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser |
| CVE-2026-66731 | 7.5 HIGH | facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS |
No comments yet