Home

Description

A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

PUBLISHED Reserved 2025-10-27 | Published 2026-01-29 | Updated 2026-02-03 | Assigner mitre

References

github.com/monkey/monkey/issues/426

github.com/...ies/blob/master/monkey/monkey-advisory-2025.md

cve.org (CVE-2025-63651)

nvd.nist.gov (CVE-2025-63651)

Download JSON