LOWCVSS 3.1Vulnerability

CVE-2026-82238

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.

Properties

severity
LOW
cvss_severity
LOW
cvss_score
3.1
retrieved_at
2026-09-25T15:10:03+00:00
score
3.1
last_source
NVD
cve_id
CVE-2026-82238
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
signal_observed_at
2026-09-25T15:10:03+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
published_at
2026-08-28T12:16:33.737
last_modified
2026-09-24T20:34:34.170

Related Entities (2)

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Time-of-check Time-of-use (TOCTOU) Race Condition

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82238 (CVSS 3.1) — Ninja Signal Threat Intelligence | Ninja Signal