Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service. | |
| Title | File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint | |
| First Time appeared |
Filebrowser
Filebrowser filebrowser |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:filebrowser:filebrowser:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Filebrowser
Filebrowser filebrowser |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T14:01:13.055Z
Reserved: 2026-09-14T11:33:51.886Z
Link: CVE-2026-90928
No data.
Status : Received
Published: 2026-09-14T13:19:30.870
Modified: 2026-09-14T14:17:19.880
Link: CVE-2026-90928
No data.
OpenCVE Enrichment
No data.
