Vulnerability Description
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 error or full process termination depending on the panic configuration.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/theopaid/Remote-Denial-of-Service-via-Reachable-Assertion-in-
- https://www.vulncheck.com/advisories/rouille-reachable-assertion-dos-via-remove-
FAQ
What is CVE-2026-66754?
CVE-2026-66754 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted pe...
How severe is CVE-2026-66754?
CVE-2026-66754 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-66754?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.