Input validation error in FileBrowser - #VU139759

 

Input validation error in FileBrowser - #VU139759

Published: July 27, 2026


Vulnerability identifier: #VU139759
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in the TUS resumable-upload endpoint and tusPatchHandler when handling PATCH requests for uploads. A remote user can send an oversized PATCH request body that exceeds the declared upload length to cause a denial of service.

The issue affects uploads where the server writes request data before enforcing the remaining expected length for the upload.


Affected software

FileBrowser

Remediation

Install security update from vendor's website.

FileBrowser - update to 2.63.19

External References

Related Security Bulletins