CVE-2025-63653: High severity monkey vulnerability
Published Jan 29, 2026
·Updated
An out-of-bounds read in the mkvhostfdtclose function (mkserver/mkvhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Affected Software
2 affected components
monkey
Monkey-project Monkey<=1.8.5
Event History
Jan 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63653?
CVE-2025-63653 has been identified as a vulnerability that can cause a Denial of Service (DoS).
2
How do I fix CVE-2025-63653?
To fix CVE-2025-63653, it is recommended to update the Monkey server to version 1.8.6 or later where this vulnerability has been addressed.
3
What type of vulnerability is CVE-2025-63653?
CVE-2025-63653 is classified as an out-of-bounds read vulnerability.
4
What impacts can arise from CVE-2025-63653?
CVE-2025-63653 may allow attackers to exploit the vulnerability to launch Denial of Service attacks on affected servers.
5
Which versions of Monkey are affected by CVE-2025-63653?
CVE-2025-63653 affects Monkey server versions up to and including 1.8.5.