Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-66731: Out-of-bounds Read in boazsegev facil.ioCVE-2026-66731 0 facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.h to compute a large positive integer from the negated value, corrupting internal state and moving the read pointer into unmapped memory resulting in a fault. Join the discussion | CVE Database V5 | 07/27/2026, 16:57:01 UTC Added: 07/27/2026, 17:07:58 UTC |
CVE-2026-66730: Loop with Unreachable Exit Condition ('Infinite Loop') in boazsegev facil.ioCVE-2026-66730 0 facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error flags, causing the calling loop to re-invoke the parser on the same buffer indefinitely, exhausting all workers and permanently disabling the server until manually restarted. Join the discussion | CVE Database V5 | 07/27/2026, 16:55:27 UTC Added: 07/27/2026, 17:07:58 UTC |
CVE-2026-66729: Out-of-bounds Read in boazsegev facil.ioCVE-2026-66729 0 facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault that crashes the handling worker with a single POST request. Join the discussion | CVE Database V5 | 07/27/2026, 16:52:34 UTC Added: 07/27/2026, 17:07:58 UTC |
CVE-2026-16653: Path Traversal in boazsegev facil.ioCVE-2026-16653 0 A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 07/23/2026, 01:15:11 UTC Added: 07/23/2026, 01:37:49 UTC |
CVE-2026-16632: Improper Input Validation in boazsegev facil.ioCVE-2026-16632 0 A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 07/22/2026, 23:45:10 UTC Added: 07/22/2026, 23:52:39 UTC |
Showing 1 to 5 of 5 results