CVE-2026-86776

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 10:22

Updated : 2026-09-10 19:58


NVD link : CVE-2026-86776

Mitre link : CVE-2026-86776

CVE.ORG link : CVE-2026-86776


JSON object : View

Products Affected

No product.

CWE
CWE-789

Memory Allocation with Excessive Size Value