What is CVE-2026-16632?
CVE-2026-16632 is an improper input validation vulnerability in the `websocket_on_protocol_error` function of the WebSocket Frame Parser in boazsegev facil.io up to version 0.7.4. The flaw can be exploited via manipulation of the `on_message` argument, potentially allowing remote attacks. Updating the library is recommended.
Azərbaycanca: CVE-2026-16632, boazsegev facil.io-nun 0.7.4 və əvvəlki versiyalarında WebSocket Frame Parser-in `websocket_on_protocol_error` funksiyasında düzgün olmayan giriş doğrulaması zəifliyidir. Bu, `on_message` arqumentinin manipulyasiyası ilə uzaqdan hücuma imkan verə bilər. Kitabxananı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of facil.io are affected by CVE-2026-16632?
This vulnerability affects boazsegev facil.io up to version 0.7.4.
What argument is manipulated to exploit CVE-2026-16632?
The `on_message` argument can be manipulated to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.