Disk Space Exhaustion Vulnerability in OpenVSX Extension Publishing
CVE-2026-89321

4.3MEDIUM

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-89321?

The OpenVSX Extension Publishing system lacks proper controls on the size of entries extracted from VSIX packages, allowing malicious publishers to exploit this oversight. By uploading a small, compressible VSIX file, they can trigger the server to generate significantly larger files in the temporary filesystem, potentially leading to disk space exhaustion. This occurs without authentication during extraction, enabling attackers to degrade server performance. As the temporary storage fills up, legitimate requests can result in server errors, such as 'No space left on device', and hinder proper functionality, although metadata and cached files may continue to operate normally.

Affected Version(s)

Eclipse OpenVSX 0.20.0 < 1.2.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jihun Kim
.