<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 15:18:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330440</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330440</link>
      <description>EUVD-2026-330440</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330440</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54092</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54092</link>
      <description>&lt;p&gt;File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the container was destroyed. This vulnerability is fixed in 2.63.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the container was destroyed. This vulnerability is fixed in 2.63.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54092</guid>
    </item>
    <item>
      <title>GHSA-w5fm-68j4-fpc4 — File Browser has a DoS Vulnerability via Public Login API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w5fm-68j4-fpc4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;### Summary
Unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the container was destroyed.&lt;/p&gt;
&lt;p&gt;### Details
When sending JSON in the body of the request to the route `api/login`, if a large password is sent, there is no checking on a maximum length password. This means that any length string can be sent to the server and it will be hashed. Specifically the function `CheckPwd` in `users/password.go` is called to hash and check to see if the user supplied password is valid, but there is no maximum length for the password checked in that function. Depending on how many concurrent requests are being made, there may be no logs about the failed login attempts.&lt;/p&gt;
&lt;p&gt;### PoC
Create a file with a large password using this command:
```bash
yes &amp;#34;thisisalongphraseithinksoyeahitisactuallyimsureitiswhatisthisisamouthwoahimcoolwheredidthiscomefromwowza&amp;#34; | head -n 10000000 &amp;gt; large-password.txt
```
This makes a file that&amp;#39;s about a gigabyte. The `n` parameter in the head function can be adjusted to increase or decrease the file size. Afterwards, run the following script to make a filebrowser container:
```bash
docker run -v filebrowser_data:/srv -v filebrowser_database:/database -v filebrowser_config:/config -p 8080:80 filebrowser/filebrowser
```&lt;/p&gt;
&lt;p&gt;After running the contain…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/filebrowser/filebrowser/v2, Go: github.com/filebrowser/filebrowser&lt;/p&gt;
&lt;p&gt;### Summary
Unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the container was destroyed.&lt;/p&gt;
&lt;p&gt;### Details
When sending JSON in the body of the request to the route `api/login`, if a large password is sent, there is no checking on a maximum length password. This means that any length string can be sent to the server and it will be hashed. Specifically the function `CheckPwd` in `users/password.go` is called to hash and check to see if the user supplied password is valid, but there is no maximum length for the password checked in that function. Depending on how many concurrent requests are being made, there may be no logs about the failed login attempts.&lt;/p&gt;
&lt;p&gt;### PoC
Create a file with a large password using this command:
```bash
yes &amp;#34;thisisalongphraseithinksoyeahitisactuallyimsureitiswhatisthisisamouthwoahimcoolwheredidthiscomefromwowza&amp;#34; | head -n 10000000 &amp;gt; large-password.txt
```
This makes a file that&amp;#39;s about a gigabyte. The `n` parameter in the head function can be adjusted to increase or decrease the file size. Afterwards, run the following script to make a filebrowser container:
```bash
docker run -v filebrowser_data:/srv -v filebrowser_database:/database -v filebrowser_config:/config -p 8080:80 filebrowser/filebrowser
```&lt;/p&gt;
&lt;p&gt;After running the contain…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w5fm-68j4-fpc4</guid>
    </item>
  </channel>
</rss>
