filebrowser 2.63.23 及之前版本在 处理程序中,在检查权限之前未能限制 WebSocket 消息的大小,导致已认证用户能够缓冲任意大的消息。攻击者可以发送超大 WebSocket 消息以耗尽服务器堆内存,无论 设置或 权限如何,均可引发拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| filebrowser | filebrowser | 0 ~ 2.63.23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90929 | 8.1 HIGH | File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup |
| CVE-2026-90930 | 6.8 MEDIUM | File Browser through 2.63.23 Path Traversal via Symlink Alias |
| CVE-2026-90928 | 6.5 MEDIUM | File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint |
No comments yet