Buffer Management Issues in Velociraptor's NTFS Parsing Library
CVE-2026-17535

6.2MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
11 August 2026

What is CVE-2026-17535?

The Velociraptor NTFS parsing library is susceptible to out-of-bounds errors and memory exhaustion vulnerabilities. These weaknesses can be exploited by attackers through maliciously crafted NTFS image files, particularly in scenarios involving forensic analysis of dead disk images. When employed in such untrusted contexts, these vulnerabilities can lead to application crashes and ultimately result in a Denial of Service, impacting system integrity and availability.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kris Kennaway (Datadog)
.