Home

Description

An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

PUBLISHED Reserved 2025-10-27 | Published 2026-01-29 | Updated 2026-02-03 | Assigner mitre

References

github.com/monkey/monkey/issues/426

github.com/...ies/blob/master/monkey/monkey-advisory-2025.md

cve.org (CVE-2025-63656)

nvd.nist.gov (CVE-2025-63656)

Download JSON