
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63657 is an out-of-bounds read vulnerability in the mk_mimetype_find function (mk_server/mk_mimetype.c) of the Monkey HTTP Server, allowing unauthenticated remote attackers to cause a Denial of Service (DoS) by sending a crafted HTTP request. It affects Monkey through commit f37e984 (versions up to and including 1.8.5). The vulnerability was discovered in October 2025, CVE IDs were requested and assigned in October 2025, and public disclosure occurred in January 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Archer Advisory).
The root cause is an out-of-bounds read (CWE-125) due to improper bounds checking in the mk_mimetype_find function within mk_server/mk_mimetype.c. When the Monkey HTTP Server processes a crafted HTTP request, the function reads beyond the allocated buffer boundary while attempting to identify the MIME type of a requested resource. Exploitation requires no authentication, no user interaction, and is achievable over the network with low attack complexity. A proof-of-concept exploit archive (monkey-poc.zip) was published alongside the advisory, and the issue is part of a broader set of nine vulnerabilities identified in commit f37e984 by researcher archersec (Archer Advisory, GitHub Issue).
Successful exploitation causes the Monkey HTTP Server to crash or become unavailable, resulting in a complete loss of availability for services hosted on the affected instance. There is no reported impact on confidentiality or integrity — the vulnerability is limited to a Denial of Service condition. Because no authentication is required, any network-accessible Monkey server running commit f37e984 or earlier (up to v1.8.5) is at risk of being taken offline by a remote attacker (Archer Advisory, Feedly).
Proof-of-concept exploit code is publicly available in the form of a PoC archive (monkey-poc.zip) attached to the GitHub issue filed by archersec, and the advisory has been indexed by NVD (Archer Advisory, GitHub Issue). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.51%, indicating a low but non-negligible probability of exploitation in the near term. CVE-2025-63657 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
mk_mimetype_find — for example, a request with an unusually long or malformed file extension that causes the function to read past buffer boundaries.mk_mimetype_find function in mk_server/mk_mimetype.c reads beyond the allocated buffer, causing a crash or abnormal termination of the Monkey server process.mk_mimetype_find context.monkey); repeated process restarts in a short time window as observed via process monitoring tools.No official patch has been released for CVE-2025-63657 as of the time of disclosure; the vulnerability remains unfix in all versions through commit f37e984 (≤ v1.8.5) (Archer Advisory). Organizations should implement network-based access controls (e.g., firewall rules, reverse proxy filtering) to restrict HTTP traffic to trusted sources only. Monitoring Monkey server processes for unexpected crashes or service interruptions is recommended as a detection measure. Users should watch the upstream Monkey project repository for patch releases and upgrade as soon as a fixed version becomes available.
Red Hat has acknowledged the vulnerability and published a security advisory page for CVE-2025-63657 (Red Hat). The vulnerability was reported by researcher archersec, who disclosed nine vulnerabilities in Monkey HTTP Server simultaneously via a GitHub issue and a detailed advisory document (GitHub Issue, Archer Advisory). No significant broader media coverage or social media discussion has been identified beyond standard vulnerability database indexing.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."