MEDIUM 6.9 NVD
CVE-2026-72813
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to a
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
References
- https://github.com/actix/actix-web/security/advisories/GHSA-gcqf-3g44-vc9p
- https://www.vulncheck.com/advisories/actix-files-before-denial-of-service-via-empty-range-
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-14 via NVD.
vulnfeed aggregates 11031 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.