SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-86776

LOW · CVSS 3.3 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

KeePass versions 2.35 through 2.61.1 are vulnerable due to improper validation of KDBX header field sizes, which can lead to excessive memory allocation when processing malicious KDBX files. This vulnerability allows attackers to exhaust system resources, potentially causing the application to crash. Users of affected KeePass versions, particularly those managing sensitive data, should prioritize updating to mitigate this low-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86776
Severity
LOW
CVSS
3.3
EPSS
0.12%

Original NVD Description

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.