A high-severity denial-of-service vulnerability, tracked as CVE-2026-66730, affects facil.io versions 0.6.0 through 0.7.6, including impacted 0.6.x, 0.7.x, and master code lines. The flaw is in the framework's multipart MIME body parser, where a malformed multipart/form-data request containing a partial closing boundary can cause http_mime_parse to consume 0 bytes without setting completion or error flags. Because the caller continues parsing the same buffer, an unauthenticated remote attacker can force a worker process into a permanent 100% CPU loop.
The bug is classified as CWE-835 and CWE-400 and carries a CVSS v3.1 score of 7.5 with high availability impact. Exploitation does not crash the server, which means affected workers may remain stuck rather than being automatically respawned; by sending enough crafted requests to match the worker count, an attacker can exhaust all workers and make the service unavailable until it is manually restarted. Public reporting says the issue stems from a missing progress guard in body parsing, and a proposed fix is to add a check in http_parse_body() to abort when parsing makes no forward progress.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A denial-of-service vulnerability affecting facil.io 0.6.0 through 0.7.6 was publicly disclosed as CVE-2026-66730. The flaw allows an unauthenticated attacker to send a malformed multipart/form-data request with a partial closing boundary and trap worker processes in an infinite 100% CPU loop, potentially exhausting all workers until manual restart.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.