Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-86776

Опубликовано: 09 сент. 2026
Источник: debian
EPSS Низкий

Описание

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keepass2unfixedpackage

Примечания

  • https://github.com/KSecur1ty/KDBX-Header-Size-Mirage-POC

EPSS

Процентиль: 2%
0.00118
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
nvd
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
github
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
fstec
около 1 месяца назад

Уязвимость функции ReadHeaderField() пароля менеджера паролей KeePass, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00118
Низкий