What is CVE-2026-66729?
CVE-2026-66729 is an integer underflow vulnerability in the multipart MIME body parser of facil.io versions 0.6.0 through 0.7.6. An unauthenticated remote attacker can crash the server process by sending a crafted Content-Disposition header with an empty field name.
Azərbaycanca: CVE-2026-66729 facil.io kitabxanasının 0.6.0-dan 0.7.6-ya qədər versiyalarında multipart MIME body parser-də tam ədəd alt daşması (integer underflow) zəifliyidir. Boş sahə adı olan xüsusi hazırlanmış Content-Disposition başlığı göndərilərək autentifikasiya olunmamış uzaqdan hücumçu server prosesini çökdürə bilər.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of facil.io are affected by CVE-2026-66729?
Versions 0.6.0 through 0.7.6 of the facil.io library are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-66729?
An unauthenticated remote attacker can crash the server process by sending a crafted Content-Disposition header.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.