Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault. Join the discussion | CVE Database V5 | 07/27/2026, 16:57:01 UTC Added: 07/27/2026, 17:07:58 UTC |
0 facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error flags, causing the calling loop to re-invoke the parser on the same buffer indefinitely, exhausting all workers and permanently disabling the server until manually restarted. Join the discussion | CVE Database V5 | 07/27/2026, 16:55:27 UTC Added: 07/27/2026, 17:07:58 UTC |
0 facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request. Join the discussion | CVE Database V5 | 07/27/2026, 16:52:34 UTC Added: 07/27/2026, 17:07:58 UTC |
0 A path traversal vulnerability exists in boazsegev facil.io up to version 0.7.58 in the http_sendfile2 function of the Public Folder Handler component. This flaw allows remote attackers to manipulate file paths, potentially accessing unauthorized files. The vulnerability has a CVSS 4.0 base score of 6.9 (medium severity). The project has been informed but has not yet responded or issued a fix. Exploit code has been publicly released. Join the discussion | CVE Database V5 | 07/23/2026, 01:15:11 UTC Added: 07/23/2026, 01:37:49 UTC |
CVE-2026-16632 is a medium severity vulnerability in boazsegev facil.io up to version 0.7.4. It involves improper input validation in the websocket_on_protocol_error function within the WebSocket Frame Parser component. This flaw allows remote attackers to manipulate the on_message argument, potentially causing unexpected behavior. An exploit has been published, but the vendor has not yet responded or provided a fix. Join the discussion | CVE Database V5 | 07/22/2026, 23:45:10 UTC Added: 07/22/2026, 23:52:39 UTC |
Showing 1 to 5 of 5 results