Junglewise Threat Intelligence

CVE-2026-66730: facil.io infinite loop in multipart body parser

CVE-2026-66730 · Severity: high · CVSS 7.5 · Published 2026-07-27

Technologies: Boaz Segev Facil.Io. Vendors: Boaz Segev.

Executive brief

facil.io is a high-performance web application framework. A flaw in how it handles web form uploads allows an unauthenticated attacker to send a specially crafted request that causes the server's processor to spin in an infinite loop. This effectively freezes the server, making it unresponsive to legitimate users and requiring a manual restart to restore service.

Technical details

A denial-of-service vulnerability exists in the multipart/form-data parser of facil.io versions 0.6.0 through 0.7.6. The root cause is a missing progress guard in the `http_parse_body` loop within `lib/facil/http/http.c`. When a request contains a partial closing boundary, the `http_mime_parse` function returns zero bytes consumed without setting the 'done' or 'error' flags. This causes the calling loop to indefinitely re-invoke the parser on the same data buffer, leading to an infinite loop (CWE-835) that consumes 100% CPU. An unauthenticated remote attacker can exhaust all available worker processes with a single request, necessitating a manual restart of the server.

Affected products

  • boazsegev facil.io 0.6.0 through 0.7.6

Timeline

  • 2026-07-27: disclosed: Vulnerability disclosed by researcher Theodosis Paidakis
  • 2026-07-27: advisory

References

Related threats