
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63653 is an out-of-bounds read vulnerability in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of the Monkey HTTP Server, affecting commit f37e984 and all versions up to and including 1.8.5. It allows unauthenticated remote attackers to cause a Denial of Service (DoS) by sending a specially crafted HTTP request. CVE IDs were requested and assigned in October 2025, with public disclosure in January 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Archer Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in the virtual host file descriptor table close function (mk_vhost_fdt_close) within mk_server/mk_vhost.c. When processing a crafted HTTP request, the function reads beyond the bounds of an allocated buffer, triggering a crash and resulting in a DoS condition. No authentication or user interaction is required, and the attack can be conducted remotely over the network with low complexity. This CVE is part of a broader set of nine vulnerabilities discovered by researcher archersec in Monkey commit f37e984, all disclosed simultaneously in January 2026 (Archer Advisory, GitHub Issue).
Successful exploitation causes the Monkey HTTP Server process to crash, resulting in a complete loss of availability for any services hosted on the affected instance. There is no confidentiality or integrity impact — the vulnerability is limited to a DoS condition. Given that Monkey is a lightweight embedded HTTP server often used in IoT and resource-constrained environments, exploitation could disrupt critical services in those contexts (Feedly, Archer Advisory).
Proof-of-concept exploit code is publicly available via the archersec security advisory and the associated GitHub issue, which includes a PoC zip archive (monkey-poc.zip) (GitHub Issue, Archer Advisory). The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it trivially exploitable by any network-accessible attacker. There is no confirmed evidence of in-the-wild exploitation at this time, and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.51%, indicating a currently low but non-negligible probability of exploitation in the near term (Feedly).
mk_vhost_fdt_close function during virtual host file descriptor cleanup. The exact triggering condition involves manipulating request parameters related to virtual host handling.mk_vhost_fdt_close function reads out of bounds, causing a crash and rendering the HTTP server unavailable (Archer Advisory, GitHub Issue).monkey or mk_server); repeated process restarts in a short time window if a supervisor/watchdog is configured.core.*) in the Monkey working directory following server crashes (Archer Advisory).As of the time of disclosure (January 2026), no official patch has been released by the Monkey project for this vulnerability — all affected versions up to and including 1.8.5 remain unpatched (Archer Advisory). Organizations should monitor the Monkey GitHub repository for patch releases. In the interim, implement network-level access controls (firewall rules, allowlists) to restrict HTTP access to the Monkey server to trusted IP ranges only. Additionally, deploy rate limiting and HTTP request filtering at a reverse proxy or WAF layer to reduce exposure, and monitor server logs for anomalous request patterns indicative of exploitation attempts.
Red Hat has acknowledged the vulnerability and published a tracking page for CVE-2025-63653, though no Red Hat products are currently listed as affected (Red Hat CVE). The vulnerability was reported by researcher archersec, who disclosed a total of nine vulnerabilities in Monkey HTTP Server simultaneously, noting that none had been fixed at the time of disclosure. The GitHub issue filed by archersec in September 2025 has been closed without a corresponding fix being merged (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."