Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90927— filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message

Quick assessment

Affected
filebrowser filebrowser
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

filebrowser 2.63.23 及之前版本在 处理程序中,在检查权限之前未能限制 WebSocket 消息的大小,导致已认证用户能够缓冲任意大的消息。攻击者可以发送超大 WebSocket 消息以耗尽服务器堆内存,无论 设置或 权限如何,均可引发拒绝服务(DoS)。

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90927

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message
Source: CVE Program / CVE List V5
Vulnerability Description
filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust server heap memory and cause denial of service regardless of EnableExec setting or Execute permission.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
filebrowser filebrowser 0 ~ 2.63.23 -

II. Public POCs for CVE-2026-90927

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90927

登录查看更多情报信息。

Vendor Advisories for CVE-2026-90927 (2)

Same Patch Batch · filebrowser · 2026-09-14 · 4 CVEs total

CVE-2026-90929 8.1 HIGH File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup
CVE-2026-90930 6.8 MEDIUM File Browser through 2.63.23 Path Traversal via Symlink Alias
CVE-2026-90928 6.5 MEDIUM File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-90927

No comments yet


Leave a comment