PT-2026-83087 · Unknown · Filebrowser
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
filebrowser versions prior to 2.63.24
Description
Insufficient validation of named pipes in the directory archive and public download handlers allows attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources, leading to a denial of service. A goroutine is a lightweight thread managed by the Go runtime.
Recommendations
Update to version 2.63.24 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filebrowser