Report: CVE-2026-41146 - facil.io and downstream iodine ruby gem vulnerable to uncontrolled resource cons

Report: CVE-2026-41146 - facil.io and downstream iodine ruby gem vulnerable to uncontrolled resource cons

CVE ID :CVE-2026-41146 Published : April 22, 2026, 2:16 a.m. | 42 minutes ago Description :facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user space and pegs one CPU core at ~100% instead of returning a parse error. Because `iodine` vendors the same parser code, the issue also affects `iodine` when it parses attacker-controlled JSON. The smallest reproducer I found is `[i`. The quoted-value form that originally exposed the issue, `[

CVE Details

Published
April 22, 2026