CVE-2026-90928

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 13:19

Updated : 2026-09-14 14:17


NVD link : CVE-2026-90928

Mitre link : CVE-2026-90928

CVE.ORG link : CVE-2026-90928


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption