CVE-2026-90928

MEDIUMCVSS 6.5/10

Last modified

CVE-2026-90928 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service..

Description

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
filebrowserfilebrowser<= 2.63.23

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90928?
File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.
How severe is CVE-2026-90928?
CVE-2026-90928 has a CVSS score of 6.5/10 (MEDIUM severity).
How do I fix CVE-2026-90928?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90928?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST