Divide by Zero Vulnerability in Velociraptor Client Software
CVE-2026-64951

3.5LOW

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
12 August 2026

What is CVE-2026-64951?

A vulnerability in the Velociraptor client software allows a rogue client to upload a malformed sparse file. When the graphical user interface (GUI) attempts to process this file, a Divide by Zero error occurs within the ShouldPadFile() function, which can result in a server crash. This flaw poses potential stability and operational risks for users running the affected versions.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani (Talence Security)
.