CVE-2026-86776 KeePass versions 2.35 through 2.61.1 fail to validate… — CVE Notify — TG.ME

🚨 CVE-2026-86776
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

🎖@cveNotify
GitHub
GitHub - KSecur1ty/KDBX-Header-Size-Mirage-POC
Contribute to KSecur1ty/KDBX-Header-Size-Mirage-POC development by creating an account on GitHub.
September 9, 2026 28 1