Executive brief
facil.io is a high-performance C framework used for building web applications and WebSocket servers. A flaw in its WebSocket parser allows remote attackers to bypass security checks by sending specially crafted data packets that lack mandatory encryption (masking). This can cause the server to process unauthorized commands or data before it realizes the connection is invalid and shuts it down, potentially leading to unintended actions or state changes in the application.
Technical details
A logic bypass vulnerability exists in the WebSocket frame parser of facil.io up to version 0.7.4. The function `websocket_on_protocol_error` in `lib/facil/http/parsers/websocket_parser.h` correctly identifies unmasked client-to-server frames (which violate RFC 6455), but the parser fails to immediately halt execution. Instead, it continues to the opcode switch statement, delivering the invalid payload to the application's `on_message` callback before the connection is terminated. A remote, unauthenticated attacker can exploit this to execute one application-level action per connection using frames that should have been rejected. As of the advisory date, the project has been informed but no official patch has been released.
Affected products
- boazsegev facil.io <= 0.7.4
Timeline
- 2026-06-17: disclosed: Issue reported on GitHub repository
- 2026-07-23: advisory: CVE published by VulDB/NVD