What is CVE-2026-66731?
A denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser in facil.io versions 0.7.5 through 0.7.6 allows unauthenticated remote attackers to crash the server. Exploitation occurs by sending a single POST request with a negative chunk size value. Immediate update of the affected versions is recommended.
Azərbaycanca: facil.io 0.7.5–0.7.6 versiyalarında HTTP/1.1 'chunked transfer encoding' parser-da autentifikasiyasız uzaqdan xidmət dayandırma (DoS) zəifliyi aşkarlanıb. Təcavüzkar mənfi 'chunk size' dəyəri ilə xüsusi POST sorğusu göndərərək serveri çökdürə bilər. Təsirlənən versiyaları dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which facil.io versions are affected by this DoS vulnerability (CVE-2026-66731)?
facil.io versions 0.7.5 through 0.7.6 are affected by this vulnerability.
How does an attacker leverage this vulnerability to crash the server?
An attacker can crash the server by sending a specially crafted POST request with a negative chunk size value to the chunked transfer encoding parser.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.