{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90928","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-09-14T11:33:51.886Z","datePublished":"2026-09-14T12:48:24.837Z","dateUpdated":"2026-09-14T14:01:13.055Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-14T12:48:24.837Z"},"datePublic":"2026-08-31T00:00:00.000Z","title":"File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint","descriptions":[{"lang":"en","value":"File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Uncontrolled Resource Consumption","cweId":"CWE-400","type":"CWE"}]}],"affected":[{"vendor":"filebrowser","product":"filebrowser","defaultStatus":"unaffected","packageURL":"pkg:golang/github.com/filebrowser/filebrowser/v2","versions":[{"version":"0","status":"affected","versionType":"semver","lessThanOrEqual":"2.63.23"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:*","versionEndIncluding":"2.63.23"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"references":[{"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-448h-jr2h-3vhp","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-448h-jr2h-3vhp)"},{"name":"VulnCheck Advisory: File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/file-browser-through-2.63.23-memory-exhaustion-via-subtitle-endpoint"}],"credits":[{"lang":"en","value":"1diot9","type":"reporter"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"references":[{"url":"https://github.com/filebrowser/filebrowser/security/advisories/GHSA-448h-jr2h-3vhp","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-14T14:00:30.915269Z","id":"CVE-2026-90928","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-14T14:01:13.055Z"}}]}}