Denial of Service in actix-files by Actix Web
CVE-2026-72813

6.9MEDIUM

Key Information:

Vendor

Actix

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-72813?

The actix-files library prior to version 0.6.10 has a vulnerability that allows remote attackers to exploit a flaw by sending a GET request with an empty Range header. This input can trigger a denial of service condition, leading to the abrupt termination of the process, especially when panic behavior is set to abort. Organizations using affected versions must prioritize updates to mitigate potential disruptions.

Affected Version(s)

actix-web 0 < 0.6.10

actix-web 0.6.10

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Diomendius
JohnTitor
.