Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5r36-v86r-vm5x

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.6
CVSS3: 3.3

Описание

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

EPSS

Процентиль: 2%
0.00118
Низкий

4.6 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 3.3
ubuntu
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
nvd
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
debian
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header fiel ...

CVSS3: 3.3
fstec
около 1 месяца назад

Уязвимость функции ReadHeaderField() пароля менеджера паролей KeePass, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00118
Низкий

4.6 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-789