CVE-2026-72813

Summary

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.

Affected Software

VendorProductVersion RangeStatus
actixactix-web0 < 0.6.10affected
actixactix-web0.6.10unaffected

Weaknesses

  • CWE-248: Uncaught Exception

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References