FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability. | |
| Title | FileBrowser before 2.63.19 Disk Exhaustion via TUS Upload | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:42.867Z
Reserved: 2026-08-10T15:13:41.486Z
Link: CVE-2026-72838
No data.
Status : Received
Published: 2026-08-14T12:16:47.313
Modified: 2026-08-14T12:16:47.313
Link: CVE-2026-72838
No data.
OpenCVE Enrichment
No data.