CVE-2026-82238

Source
https://cve.org/CVERecord?id=CVE-2026-82238
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82238.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82238
Aliases
  • GHSA-4r8p-gqj2-mwgm
Downstream
CGA (4)
Published
2026-08-28T10:49:27Z
Modified
2026-10-02T03:30:21Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads
Details

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-367"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82238.json"
}
References

Affected packages

Git / github.com/filebrowser/filebrowser

Affected ranges

Type
GIT
Repo
https://github.com/filebrowser/filebrowser
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.24.0"
        },
        {
            "last_affected":  "2.63.23"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.24.0
v2.24.1
v2.24.2
v2.25.0
v2.26.0
v2.27.0
v2.28.0
v2.29.0
v2.30.0
v2.31.0
v2.31.1
v2.31.2
v2.32.0
v2.32.1
v2.32.2
v2.32.3
v2.33.0
v2.33.1
v2.33.10
v2.33.2
v2.33.3
v2.33.4
v2.33.5
v2.33.6
v2.33.7
v2.33.8
v2.33.9
v2.34.0
v2.34.1
v2.34.2
v2.35.0
v2.36.0
v2.36.1
v2.36.2
v2.36.3
v2.37.0
v2.38.0
v2.39.0
v2.40.0
v2.40.1
v2.40.2
v2.41.0
v2.42.0
v2.42.1
v2.42.2
v2.42.3
v2.42.4
v2.42.5
v2.43.0
v2.44.0
v2.44.1
v2.44.2
v2.45.0
v2.45.1
v2.45.2
v2.45.3
v2.46.0
v2.46.1
v2.47.0
v2.48.0
v2.48.1
v2.48.2
v2.49.0
v2.50.0
v2.51.0
v2.51.1
v2.51.2
v2.52.0
v2.53.0
v2.53.1
v2.54.0
v2.55.0
v2.56.0
v2.57.0
v2.57.1
v2.58.0
v2.59.0
v2.60.0
v2.61.0
v2.61.1
v2.61.2
v2.62.0
v2.62.1
v2.62.2
v2.63.0
v2.63.1
v2.63.10
v2.63.11
v2.63.12
v2.63.13
v2.63.14
v2.63.15
v2.63.16
v2.63.17
v2.63.18
v2.63.19
v2.63.20
v2.63.21
v2.63.22
v2.63.23
v2.63.3
v2.63.4
v2.63.5
v2.63.6
v2.63.7
v2.63.8
v2.63.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82238.json"