File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service. | |
| Title | File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint | |
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T14:01:13.055Z
Reserved: 2026-09-14T11:33:51.886Z
Link: CVE-2026-90928
No data.
Status : Received
Published: 2026-09-14T13:19:30.870
Modified: 2026-09-14T14:17:19.880
Link: CVE-2026-90928
No data.
OpenCVE Enrichment
No data.
Weaknesses