Junglewise Threat Intelligence

CVE-2026-16653: boazsegev facil.io path traversal in Public Folder Handler

CVE-2026-16653 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Technologies: Boaz Segev Facil.Io. Vendors: Boaz Segev.

Executive brief

facil.io is a high-performance web application framework for the C programming language. A security flaw in its static file handler allows remote attackers to access files outside of the designated public folder. This could lead to the exposure of sensitive information, such as configuration files, application source code, or system logs, depending on the server's permissions.

Technical details

A path traversal vulnerability exists in the facil.io web framework when the .public_folder configuration is enabled. The vulnerability resides in the http_sendfile2 function within lib/facil/http/http.c. While the framework uses http_test_encoded_path() to detect traversal sequences like '/../', it fails to validate request paths that begin directly with '../'. Because the HTTP/1 parser accepts request targets that do not start with a forward slash, an unauthenticated remote attacker can craft a GET request (e.g., 'GET ../secret.txt') to escape the intended static file root. This allows for the unauthorized reading of arbitrary files accessible to the server process. As of the advisory date, no patch has been released.

Affected products

  • boazsegev facil.io up to 0.7.58

Timeline

  • 2026-06-17: disclosed: Issue reported via GitHub issue #170
  • 2026-07-23: advisory: CVE published and added to NVD

References

Related threats