PT-2026-91281 · Dotvvm · Dotvvm

CVE-2026-57581

·

Published

2026-09-14

·

Updated

2026-09-16

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions DotVVM versions prior to 4.2.11 DotVVM versions prior to 4.3.15 DotVVM versions prior to 5.0.0-preview09-final
Description Applications using configured file upload storage allow unauthenticated users to submit files directly to the DotvvmFileUploadMiddleware without a required X-DotVVM-UploadToken generated by the FileUpload component. This allows an attacker to repeatedly upload files to fill the application storage, resulting in a denial of service.
Recommendations Update to version 4.2.11. Update to version 4.3.15. Update to version 5.0.0-preview09-final. Use DotvvmConfiguration.Security.AuthorizeFileUpload to restrict which users are permitted to upload files.

Exploit

Fix

DoS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57581
GHSA-2RM3-333W-XVC4

Affected Products

Dotvvm