Description
A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Published: 2026-09-16
Score: 7.5 High
EPSS: 1.4% Low
KEV: No
Impact: Denial of Service via crafted HTTP request
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a null pointer dereference in the mk_sched_event_close function within the Monkey server code. A malicious actor can send a specially crafted HTTP request that triggers the dereference, leading to an application crash and the inability to serve legitimate traffic. The failure is localized to the Monkey process and results in service disruption but does not affect wider system confidentiality or integrity.

Affected Systems

The affected software is the Monkey server. No specific vendor or product list is provided in the CNA data. Version information is unknown, but the flaw exists in code preceding commit 4fb0c16. Operators should verify the installed Monkey version and review code commits for this issue.

Risk and Exploitability

The exploit is possible when an attacker can reach the Monkey HTTP endpoint, which is a remote network-based attack vector. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the fault can still be readily triggered by an attacker with network access, leading to a high impact denial of service that could affect availability of dependent services. The CVSS score of 7.5 indicates high severity.

Generated by OpenCVE AI on September 22, 2026 at 19:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Monkey to a version that includes the commit following 4fb0c16, ensuring the null pointer dereference is addressed.
  • Restart the Monkey service after the upgrade to apply the new code and eliminate any running instances that may still be vulnerable.
  • Configure network filtering or a WAF rule to block malformed HTTP requests targeting mk_sched_event_close until the patch is applied.

Generated by OpenCVE AI on September 22, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in mk_sched_event_close Leads to DoS via HTTP Request

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in mk_sched_event_close Leads to DoS via HTTP Request
Weaknesses CWE-476

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T16:08:13.714Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38999

cve-icon Vulnrichment

Updated: 2026-09-22T16:05:33.740Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:17:14.660

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-38999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:30:14Z

Weaknesses