Memory Exhaustion Vulnerability in KeePass by Dominik Reichl
CVE-2026-86776
Key Information:
Badges
What is CVE-2026-86776?
The KeePass password manager, specifically versions 2.35 through 2.61.1, contains a vulnerability that stems from inadequate validation of KDBX header field sizes during memory allocation. This flaw allows attackers to create specially crafted KDBX files that specify excessively large header field lengths. When the affected application processes such files, it may allocate vast amounts of memory, potentially leading to resource exhaustion and application crashes. Users are encouraged to update to the latest version to mitigate this risk.
Affected Version(s)
KeePass 2.35 <= 2.61.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
