SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82235

MEDIUM · CVSS 5.9 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Filebrowser versions up to 2.63.23 are vulnerable due to inadequate validation of named pipes in directory archive and public download handlers. This flaw allows both authenticated users and anonymous visitors with public share links to exploit the system by repeatedly requesting archives containing named pipes, potentially leading to resource exhaustion and denial of service. Organizations utilizing Filebrowser should prioritize addressing this vulnerability to prevent service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82235
Severity
MEDIUM
CVSS
5.9
EPSS
0.39%

Original NVD Description

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.