MEDIUMCVSS 5.9Vulnerability

CVE-2026-82235

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.

Properties

severity
MEDIUM
cvss_severity
MEDIUM
cvss_score
5.9
retrieved_at
2026-09-25T15:10:03+00:00
score
5.9
last_source
NVD
cve_id
CVE-2026-82235
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-25T15:10:03+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-28T12:16:33.267
last_modified
2026-09-24T20:34:34.170

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Resource Consumption

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82235 (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal