What is CVE-2026-66754?
A reachable assertion vulnerability exists in the `Request::remove_prefix` function of the Rouille web framework versions 0.1.6 through 3.6.2. Remote unauthenticated attackers can crash the server by sending a crafted percent-encoded URL whose decoded path matches a configured prefix. Users are advised to update to the latest version.
Azərbaycanca: Rouille veb server framework-inin 0.1.6-dən 3.6.2-dək versiyalarında `Request::remove_prefix` funksiyasında əldə edilə bilən assertion zəifliyi aşkar edilib. Uzaqdan autentifikasiya olunmamış hücumçu xüsusi hazırlanmış faizlə kodlanmış URL göndərərək serveri çökdürə bilər. İstifadəçilərə ən son versiyaya yeniləmə tövsiyə olunur.
FAQ2
Which versions of the Rouille framework are affected by CVE-2026-66754?
Rouille versions 0.1.6 through 3.6.2 are affected by this vulnerability.
Is authentication required to exploit CVE-2026-66754?
No, remote unauthenticated attackers can crash the server by sending a crafted URL.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.