A vulnerability classified as critical has been found in boazsegev facil.io up to 0.7.4. Affected is the function
websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame Parser. This manipulation of the argument on_message causes improper input validation.
This vulnerability is handled as CVE-2026-16632. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.