KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 10:22
Updated : 2026-09-10 19:58
NVD link : CVE-2026-86776
Mitre link : CVE-2026-86776
CVE.ORG link : CVE-2026-86776
JSON object : View
Products Affected
No product.
CWE
CWE-789
Memory Allocation with Excessive Size Value
