Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86776

LOW NVD
CVSS Score 3.3
Severity LOW
Published Sep 09, 2026
Vendor unknown

Description

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

References