Integer overflow in keepassxc - #VU151867
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer overflow in the KDB 1 importer parseGroupTreeState() function when importing a crafted KDB file. A remote attacker can provide a crafted KDB file with a record tree state count that causes an out-of-bounds read to cause a denial of service.
User interaction is required to import the crafted KDB file.