A high-severity denial-of-service flaw tracked as CVE-2026-66731 affects facil.io versions 0.7.5 through 0.7.6, with reporting also indicating exposure in master. The bug is in the HTTP/1.1 chunked transfer encoding parser, where a negative hexadecimal chunk size can be accepted and converted into a large positive integer, corrupting parser state and moving a read pointer into unmapped memory. An unauthenticated attacker can trigger the crash remotely with a single crafted POST request using Transfer-Encoding: chunked, making the issue low-complexity and network exploitable.
Advisories say the flaw was introduced when the 0.8.x HTTP/1.1 parser was backported into 0.7.5, specifically through http1_atol16 accepting a leading minus sign. A proof of concept has been noted, and CISA SSVC metadata marks exploitation as automatable with partial technical impact. Researchers also warned that the special case -0 may not crash the server but could create a request-smuggling primitive in proxy deployments that interpret chunked encoding differently; recommended fixes include rejecting signed chunk sizes in http1_atol16 or validating that chunk_len is non-negative before use.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A denial-of-service vulnerability affecting facil.io 0.7.5 through 0.7.6 was publicly disclosed. The flaw allows an unauthenticated remote attacker to crash the server with a single crafted HTTP/1.1 chunked POST request using a negative chunk size value.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.