PT-2026-91281 · Dotvvm · Dotvvm
CVE-2026-57581
·
Published
2026-09-14
·
Updated
2026-09-16
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
DotVVM versions prior to 4.2.11
DotVVM versions prior to 4.3.15
DotVVM versions prior to 5.0.0-preview09-final
Description
Applications using configured file upload storage allow unauthenticated users to submit files directly to the
DotvvmFileUploadMiddleware without a required X-DotVVM-UploadToken generated by the FileUpload component. This allows an attacker to repeatedly upload files to fill the application storage, resulting in a denial of service.Recommendations
Update to version 4.2.11.
Update to version 4.3.15.
Update to version 5.0.0-preview09-final.
Use
DotvvmConfiguration.Security.AuthorizeFileUpload to restrict which users are permitted to upload files.Exploit
Fix
DoS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dotvvm