CVE-2026-86776

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

Scoring

Severity
MEDIUM
CVSS base score
4.6
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CWE
CWE-789
Published
2026-09-09
Last modified
2026-09-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs