SB2026100630 - Multiple vulnerabilities in HFS
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) (CVE-ID: CVE-2026-61500)
CWE-ID: CWE-338 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to forge authenticated sessions.
The vulnerability exists due to use of predictable random values in session and login-handshake identifiers when generating session-related secrets. A remote attacker can predict application pseudorandom values to forge authenticated sessions.
2) Cross-site scripting (CVE-ID: CVE-2026-61501)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in an administrator's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the administrative log viewer when rendering failed-login log entries. A remote attacker can submit a failed login attempt containing malicious script content to execute arbitrary script in an administrator's browser.
User interaction is required to view the affected log entry.
3) Cross-site request forgery (CVE-ID: CVE-2026-61502)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized state-changing API operations.
The vulnerability exists due to improper cross-site request forgery protection in GET API handling when a browser sends a crafted GET request to a state-changing API. A remote attacker can trick a user into visiting a crafted URL to perform unauthorized state-changing API operations.
4) Path traversal (CVE-ID: CVE-2026-61505)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in language-code handling when processing a crafted lang parameter. A remote attacker can send a request containing path traversal sequences to disclose information.
5) Cross-site scripting (CVE-ID: CVE-2026-61504)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in basic directory listings when rendering a crafted filename. A remote user can create a file with a malicious filename to execute arbitrary script in a victim's browser.
User interaction is required to view the affected basic directory listing.
6) Protection mechanism failure (CVE-ID: CVE-2026-61503)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass anti-brute-force login protections.
The vulnerability exists due to failure to invoke the failed-login event in the login API when handling an invalid username. A remote attacker can repeatedly submit login initiation requests with invalid usernames to bypass anti-brute-force login protections.
The issue affects plugin handling of failed login attempts for invalid usernames.
Remediation
Install update from vendor's website.
References
- https://github.com/rejetto/hfs/releases/tag/v3.2.1
- https://github.com/rejetto/hfs/commit/59472e534bf7e056d708382d02935c2eaf956927
- https://github.com/rejetto/hfs/compare/v3.2.0...v3.2.1
- https://github.com/rejetto/hfs/commit/b555efda2c927295540bb4bf08dd2339e12b2038
- https://github.com/rejetto/hfs/commit/a1c6cc0a0568e03619573e0fc079c07a4a1faef6
- https://github.com/rejetto/hfs/commit/10f4c9942e194ac779a0aa630051406ed5c89af1
- https://github.com/rejetto/hfs/commit/abe15df901c65562a3be5f5e068bf8fef976f9f3
- https://github.com/rejetto/hfs/commit/ac07a062ca85ba3bf6b464a1ccd05291c7495d98