MEDIUMVulnerability

CVE-2026-72838

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability.

Properties

severity
MEDIUM
score
6.5
epss_score
0.00295
cve_id
CVE-2026-72838
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-14T12:16:47.313
last_modified
2026-09-08T20:32:39.347
epss_percentile
0.21785

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72838 — Ninja Signal Threat Intelligence | Ninja Signal