Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55497— Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)

Quick assessment

Affected
cloudreve cloudreve
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cloudreve是中国Cloudreve团队开源的一个支持多家云存储驱动的公有云文件系统。 Cloudreve 4.17.0之前版本存在资源管理错误漏洞,该漏洞源于内置缩略图和头像图像解码器限制压缩文件大小但未限制解码像素尺寸,可能导致经过身份验证的用户提交小型PNG、JPEG或GIF触发无界分配,造成内存耗尽并使Cloudreve进程终止。

CVSS 6.5 · Medium EPSS 0.29% · P22

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
cloudreve cloudreve < 4.17.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55497

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
Source: CVE Program / CVE List V5
Vulnerability Description
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates the Cloudreve process through fatal out-of-memory behavior. This issue is fixed in version 4.17.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5
Vulnerability Title
Cloudreve 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cloudreve是中国Cloudreve团队开源的一个支持多家云存储驱动的公有云文件系统。 Cloudreve 4.17.0之前版本存在资源管理错误漏洞,该漏洞源于内置缩略图和头像图像解码器限制压缩文件大小但未限制解码像素尺寸,可能导致经过身份验证的用户提交小型PNG、JPEG或GIF触发无界分配,造成内存耗尽并使Cloudreve进程终止。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
cloudreve cloudreve < 4.17.0 -

II. Public POCs for CVE-2026-55497

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55497

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55497 (1)

Vendor Advisories for CVE-2026-55497 (1)

Vendor Pages for CVE-2026-55497 (1)

Same Patch Batch · cloudreve · 2026-07-31 · 6 CVEs total

CVE-2026-55502 7.1 HIGH Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials
CVE-2026-62323 6.3 MEDIUM Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ign
CVE-2026-55495 4.3 MEDIUM Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Acc
CVE-2026-55496 4.3 MEDIUM Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because Searc
CVE-2026-55499 4.3 MEDIUM Cloudreve: Broken access control in file event stream leaks activity events for unshared s

IV. Related Vulnerabilities

V. Comments for CVE-2026-55497

No comments yet


Leave a comment