CVE-2025-63657: High severity monkey vulnerability
Published Jan 29, 2026
·Updated
An out-of-bounds read in the mkmimetypefind function (mkserver/mkmimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Affected Software
2 affected components
monkey
Monkey-project Monkey<=1.8.5
Event History
Jan 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63657?
CVE-2025-63657 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2025-63657?
To fix CVE-2025-63657, update the Monkey server to version 1.8.6 or later as it contains the necessary patches.
3
What impact does CVE-2025-63657 have on affected systems?
CVE-2025-63657 allows attackers to send crafted HTTP requests that can lead to an out-of-bounds read, potentially causing a Denial of Service.
4
Which versions of Monkey are affected by CVE-2025-63657?
CVE-2025-63657 affects Monkey versions up to and including 1.8.5.
5
What component is primarily involved in CVE-2025-63657?
The mk_mimetype_find function in mk_server/mk_mimetype.c is the component primarily involved in CVE-2025-63657.