Filebrowser Denial of Service via Named Pipes Vulnerability
CVE-2026-82235
8.2HIGH
What is CVE-2026-82235?
A vulnerability in Filebrowser versions prior to 2.63.23 allows for denial of service due to improper validation of named pipes within directory archive and public download handlers. This issue permits both authenticated users and unauthenticated visitors with public share links to issue repeated requests for archives containing named pipes. As a result, this can lead to excessive blocking open syscalls, causing the server's goroutines to pin and exhaust its connection resources, significantly impacting availability.
Affected Version(s)
filebrowser 0 <= 2.63.23
