CVE-2026-41146: falha de alta gravidade em boazsegev facil.io
facil.io and downstream iodine ruby gem vulnerable to uncontrolled resource consumption and loop with unreachable exit condition
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.7epss 0.4%
probabilidade de exploração
0.4%top 65% das CVEs
exploração observada
nãonenhuma fonte reporta
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user space and pegs one CPU core at ~100% instead of returning a parse error. Because `iodine` vendors the same parser code, the issue also affects `iodine` when it parses attacker-controlled JSON. The smallest reproducer I found is `[i`. The quoted-value form that originally exposed the issue, `[""i`, reaches the same bug because the parser tolerates missing commas and then treats the trailing `i` as the start of another value. Commit 5128747363055201d3ecf0e29bf0a961703c9fa0 fixes the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVEs relacionadas — boazsegev facil.io
No mesmo produto, das mais perigosas para as menos.
CVE-2026-66731HIGHfacil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoSEPSS 0.8%CVE-2026-66730HIGHfacil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body ParserEPSS 0.8%CVE-2026-66729HIGHfacil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body ParserEPSS 0.8%CVE-2026-16653MEDIUMboazsegev facil.io Public Folder http.c http_sendfile2 path traversalEPSS 0.7%CVE-2026-16632MEDIUMboazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validationEPSS 0.5%