Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources. | |
| Title | filebrowser through 2.63.23 Denial of Service via named pipes | |
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T15:53:04.375Z
Reserved: 2026-08-28T10:37:04.620Z
Link: CVE-2026-82235
No data.
Status : Received
Published: 2026-08-28T12:16:33.267
Modified: 2026-08-28T12:16:33.267
Link: CVE-2026-82235
No data.
OpenCVE Enrichment
Updated: 2026-08-28T16:12:36Z
-
CWE-400
Uncontrolled Resource Consumption