# CVE-2026-64951

## Summary

- **CVE ID:** CVE-2026-64951
- **Severity:** LOW
- **CVSS Score:** 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
- **CWE:** CWE-369
- **Published:** Aug 12, 2026
- **Last Modified:** Aug 12, 2026

## Description

A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process.

The problem is a Divide by Zero bug in the ShouldPadFile() function.

## Affected Products

- Rapid7 — Velociraptor (0)

## References

- [CNA](http://docs.velociraptor.app/announcements/advisories/cve-2026-64951/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._