What is CVE-2026-16653?
A path traversal vulnerability has been identified in the http_sendfile2 function of the Public Folder Handler component in boazsegev facil.io up to version 0.7.58. This flaw allows remote attackers to manipulate file paths and gain unauthorized access to the file system. Users are advised to upgrade to the latest version or restrict public folder services immediately.
Azərbaycanca: boazsegev facil.io v0.7.58-dək olan versiyalarda Public Folder Handler komponentinin http_sendfile2 funksiyasında path traversal zəifliyi aşkar edilib. Bu boşluq uzaqdan hücum edən şəxsə fayl sistemi üzrə icazəsiz giriş əldə etməyə imkan verir. İstifadəçilərə dərhal ən son versiyaya yeniləmə və ya ictimai qovluq xidmətlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which component and function of facil.io was CVE-2026-16653 discovered?
The vulnerability was discovered in the http_sendfile2 function of the Public Folder Handler component.
What measures should be taken to protect against the CVE-2026-16653 path traversal vulnerability?
Users are advised to upgrade to the latest version or restrict public folder services immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.