HIGH 7.1 NVD
CVE-2026-90927
filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffe
filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust server heap memory and cause denial of service regardless of EnableExec setting or Execute permission.
References
- https://github.com/filebrowser/filebrowser/security/advisories/GHSA-39cx-23x9-5c8p
- https://www.vulncheck.com/advisories/filebrowser-through-2.63.23-denial-of-service-via-unb
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-14 via NVD.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.