云虫漏洞库

CVE-2026-82238 - filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads. - 漏洞详情

漏洞编号:CVE-2026-82238

风险等级:低危

漏洞来源:CVE

CVE 编号:CVE-2026-82238

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-367

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.

相关链接

相关漏洞

« 返回首页