Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-86776

Опубликовано: 09 сент. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.3

Описание

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

Показывать по

EPSS

Процентиль: 2%
0.00118
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
debian
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header fiel ...

CVSS3: 3.3
github
8 дней назад

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

CVSS3: 3.3
fstec
около 1 месяца назад

Уязвимость функции ReadHeaderField() пароля менеджера паролей KeePass, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00118
Низкий

3.3 Low

CVSS3