Filebrowser Denial of Service via Named Pipes Vulnerability
CVE-2026-82235

8.2HIGH

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-82235?

A vulnerability in Filebrowser versions prior to 2.63.23 allows for denial of service due to improper validation of named pipes within directory archive and public download handlers. This issue permits both authenticated users and unauthenticated visitors with public share links to issue repeated requests for archives containing named pipes. As a result, this can lead to excessive blocking open syscalls, causing the server's goroutines to pin and exhaust its connection resources, significantly impacting availability.

Affected Version(s)

filebrowser 0 <= 2.63.23

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.