CVE-2025-63653
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-29

Last updated on: 2026-02-13

Assigner: MITRE

Description
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-29
Last Modified
2026-02-13
Generated
2026-06-16
AI Q&A
2026-01-29
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
monkey-project monkey to 1.8.5 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read in the mk_vhost_fdt_close function of the monkey server software. It occurs when the server processes a specially crafted HTTP request, which can cause the server to read memory outside the intended bounds.

Impact Analysis

An attacker can exploit this vulnerability to cause a Denial of Service (DoS) on the server, making the service unavailable to legitimate users.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-63653. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart