Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust server heap memory and cause denial of service regardless of EnableExec setting or Execute permission. | |
| Title | filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message | |
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T12:48:24.176Z
Reserved: 2026-09-14T11:33:51.885Z
Link: CVE-2026-90927
No data.
Status : Received
Published: 2026-09-14T13:19:30.710
Modified: 2026-09-14T13:19:30.710
Link: CVE-2026-90927
No data.
OpenCVE Enrichment
No data.
-
CWE-400
Uncontrolled Resource Consumption