Facil.Io · Facil.Io · CVE-2026-16632
**Name of the Vulnerable Software and Affected Versions**
boazsegev facil.io versions prior to 0.7.5
**Description**
Improper input validation occurs in the WebSocket Frame Parser component within the library `lib/facil/http/parsers/websocket parser.h`. The issue resides in the `websocket on protocol error()` function, where manipulation of the `on message` argument allows for a remote attack.
**Recommendations**
As a temporary workaround, restrict access to the `websocket on protocol error()` function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.