Unknown · Filebrowser · CVE-2026-72838
**Name of the Vulnerable Software and Affected Versions**
FileBrowser versions prior to 2.63.19
**Description**
Authenticated users can write arbitrary data to disk because the software fails to enforce the declared `Upload-Length` in the TUS resumable-upload PATCH endpoint. This allows attackers to send oversized request bodies that exceed the declared upload length, potentially exhausting available disk space and causing service unavailability.
**Recommendations**
Update to version 2.63.19 or later.