FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-14 12:16
Updated : 2026-09-08 20:32
NVD link : CVE-2026-72838
Mitre link : CVE-2026-72838
CVE.ORG link : CVE-2026-72838
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
