CVE-2026-66731: Out-of-bounds Read in boazsegev facil.io
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault.
AI Analysis
Technical Summary
CVE-2026-66731 affects facil.io versions 0.7.5 through 0.7.6. The vulnerability exists in the HTTP/1.1 chunked transfer encoding parser, specifically in http1_parser.h. When processing a chunked POST request, if the chunk size field contains a leading minus sign (negative value), the parser incorrectly converts this into a large positive integer. This corrupts internal parser state and causes the read pointer to move into unmapped memory, resulting in a server crash (denial-of-service). The flaw can be triggered remotely by unauthenticated attackers sending a single malicious request.
Potential Impact
Successful exploitation results in a denial-of-service condition by crashing the facil.io server. This can disrupt availability of services relying on facil.io. There is no indication of code execution or data leakage from the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is documented in the provided data. Until a patch is available, consider filtering or blocking suspicious chunked transfer encoding requests with negative chunk sizes at network or application layers.
CVE-2026-66731: Out-of-bounds Read in boazsegev facil.io
Description
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-66731 affects facil.io versions 0.7.5 through 0.7.6. The vulnerability exists in the HTTP/1.1 chunked transfer encoding parser, specifically in http1_parser.h. When processing a chunked POST request, if the chunk size field contains a leading minus sign (negative value), the parser incorrectly converts this into a large positive integer. This corrupts internal parser state and causes the read pointer to move into unmapped memory, resulting in a server crash (denial-of-service). The flaw can be triggered remotely by unauthenticated attackers sending a single malicious request.
Potential Impact
Successful exploitation results in a denial-of-service condition by crashing the facil.io server. This can disrupt availability of services relying on facil.io. There is no indication of code execution or data leakage from the provided information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is documented in the provided data. Until a patch is available, consider filtering or blocking suspicious chunked transfer encoding requests with negative chunk sizes at network or application layers.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-27T16:27:47.646Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a67906e9c2644c7f885e458
Added to database: 07/27/2026, 17:07:58 UTC
Last enriched: 08/06/2026, 16:37:24 UTC
Last updated: 09/10/2026, 19:36:55 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.