Junglewise Threat Intelligence

CVE-2026-41146: facil.io and iodine infinite loop in JSON parser

CVE-2026-41146 · Severity: high · CVSS 4 · Published 2026-04-14

Technologies: iodine (RubyGems), Boaz Segev Facil.Io. Vendors: Boaz Segev, RubyGems.

Executive brief

A vulnerability in the facil.io C framework and the iodine Ruby gem can cause web servers to stop responding. When these libraries process a specially crafted JSON message, they enter an infinite loop that consumes 100% of a CPU core. This allows a remote attacker to crash or significantly slow down a service by sending a single malicious request.

Technical details

An uncontrolled resource consumption vulnerability exists in the 'fio_json_parse' function within 'fio_json_parser.h'. The parser fails to advance the read pointer when it encounters a nested JSON value starting with 'i' or 'I' (e.g., '[i' or '[""i'). Specifically, the numeral handling logic incorrectly accepts these characters as integers without consuming any input, causing the parser to loop indefinitely on the same position while 'parser->depth' remains greater than zero. This results in a denial-of-service (DoS) condition where a single worker thread or process pegs a CPU core at 100%. The issue affects facil.io directly and the iodine Ruby gem, which vendors the vulnerable parser code. No official patch was noted in the advisory, though a code-level fix was suggested.

Affected products

  • boazsegev facil.io <= 0.7.6
  • boazsegev iodine <= 0.7.58

Timeline

  • 2026-04-14: advisory: Original GHSA publication date
  • 2026-06-08: other: Advisory updated

References

Related threats