Disk Space Exhaustion Vulnerability in OpenVSX Extension Publishing
CVE-2026-89321
4.3MEDIUM
What is CVE-2026-89321?
The OpenVSX Extension Publishing system lacks proper controls on the size of entries extracted from VSIX packages, allowing malicious publishers to exploit this oversight. By uploading a small, compressible VSIX file, they can trigger the server to generate significantly larger files in the temporary filesystem, potentially leading to disk space exhaustion. This occurs without authentication during extraction, enabling attackers to degrade server performance. As the temporary storage fills up, legitimate requests can result in server errors, such as 'No space left on device', and hinder proper functionality, although metadata and cached files may continue to operate normally.
Affected Version(s)
Eclipse OpenVSX 0.20.0 < 1.2.0
