CVE-2026-86776
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Summary
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| KeePass | KeePass | 2.35 <= 2.61.1 | affected |
Weaknesses
- CWE-789: Memory Allocation with Excessive Size Value
References
- https://github.com/KSecur1ty/KDBX-Header-Size-Mirage-POC
- https://keepass.info/
- https://keepass.info/download.html
- https://www.vulncheck.com/advisories/keepass-2.35-through-2.61.1-memory-exhaustion-via-kdbx-header-field-size
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.