PT-2026-96795 · Cloudreve · Cloudreve

CVE-2026-77633

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Cloudreve versions prior to 4.18.0
Description An authenticated user with Files.Write permission can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition in the PrepareUpload function within pkg/filemanager/fs/dbfs/upload.go. The system separates the storage quota check, performed by validateUserCapacity(), from the actual storage charge, performed by CommitWithStorageDiff(), into two non-atomic steps. This allows a user to issue concurrent upload-session requests that all read the same stale in-memory storage snapshot and pass the MaxStorage check simultaneously.
This flaw can be used to reserve storage far exceeding the account quota and the host's physical disk capacity. By completing these chunked uploads, an attacker can exhaust the host storage, resulting in a denial of service that prevents other users from uploading files. The default local-storage policy and default User group are affected.
Recommendations Update Cloudreve to version 4.18.0.

Exploit

Fix

Allocation of Resources Without Limits

Race Condition

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77633
GHSA-XJ3H-WWXQ-GFCJ

Affected Products

Cloudreve