CVE-2025-63649: High severity Monkey Monkey vulnerability
An out-of-bounds read in the httpparsertransferencodingchunked function (mkserver/mkhttpparser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63649?
CVE-2025-63649 has a severity rating that indicates it can be exploited to cause Denial of Service (DoS).
How do I fix CVE-2025-63649?
To fix CVE-2025-63649, update the Monkey server to a version later than 1.8.5 that contains the patch for this vulnerability.
Which versions of Monkey are affected by CVE-2025-63649?
CVE-2025-63649 affects all versions of the Monkey server up to and including version 1.8.5.
What kind of attack can CVE-2025-63649 facilitate?
CVE-2025-63649 allows attackers to conduct a Denial of Service (DoS) attack by sending a specially crafted POST request.
Is there a public exploit for CVE-2025-63649?
As of now, there is no widely known public exploit available for CVE-2025-63649, but the vulnerability itself poses a significant risk.