PT-2026-63528 · Boazsegev · Facil.Io

·

CVE-2026-16632

·

Publicado

2026-07-22

·

Atualizado

2026-07-23

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket on protocol error in the library lib/facil/http/parsers/websocket parser.h of the component WebSocket Frame Parser. This manipulation of the argument on message causes improper input validation. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16632

Produtos afetados

Facil.Io