PT-2026-96795 · Cloudreve · Cloudreve
CVE-2026-77633
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Cloudreve versions prior to 4.18.0
Description
An authenticated user with
Files.Write permission can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition in the PrepareUpload function within pkg/filemanager/fs/dbfs/upload.go. The system separates the storage quota check, performed by validateUserCapacity(), from the actual storage charge, performed by CommitWithStorageDiff(), into two non-atomic steps. This allows a user to issue concurrent upload-session requests that all read the same stale in-memory storage snapshot and pass the MaxStorage check simultaneously.This flaw can be used to reserve storage far exceeding the account quota and the host's physical disk capacity. By completing these chunked uploads, an attacker can exhaust the host storage, resulting in a denial of service that prevents other users from uploading files. The default local-storage policy and default
User group are affected.Recommendations
Update Cloudreve to version 4.18.0.
Exploit
Fix
Allocation of Resources Without Limits
Race Condition
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudreve