{"id":"CVE-2026-72813","title":"actix-files: actix-files: Denial of Service via empty Range header in GET requests (CVE-2026-72813)","summary":"A flaw was found in actix-files. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by sending a GET request with an empty Range header when the application is configured to abort on panic. This can lead to th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-617","vendor":"Red Hat","product":"Red Hat OpenShift Update Service","affected":["openshift_update_service"],"patched":["actix-files 0.6.10"],"published":"2026-08-14","updated":"2026-09-18","sourceUpdated":"2026-09-18T07:46:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-72813.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-72813.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-72813"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515998"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72813"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72813"},{"url":"https://github.com/actix/actix-web/security/advisories/GHSA-gcqf-3g44-vc9p"},{"url":"https://www.vulncheck.com/advisories/actix-files-before-denial-of-service-via-empty-range-header"},{"url":"https://github.com/actix/actix-web"},{"url":"https://github.com/actix/actix-web/blob/0383f4bdd1210e726143ca1ebcf01169b67a4b6c/actix-files/src/named.rs#L530-L535"}],"tags":["csaf","vex","red-hat","osv","rust"],"epss":0.00394,"epssPercentile":0.33379,"aliases":["GHSA-gcqf-3g44-vc9p"],"ecosystem":"rust","ingestedAt":"2026-08-15T19:19:54.457Z","slug":"CVE-2026-72813","body":"## Overview\n\nA flaw was found in actix-files. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by sending a GET request with an empty Range header when the application is configured to abort on panic. This can lead to the application crashing on demand.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat OpenShift Update Service · no fix planned: Red Hat OpenShift Update Service · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-72813.json)\n\n**actix-files: actix-files: Denial of Service via empty Range header in GET requests** — rated Important by Red Hat. Released 2026-08-14, updated 2026-09-18.\n\nAffected:\n\n- Red Hat OpenShift Update Service\n\nNo fix planned:\n\n- Red Hat OpenShift Update Service\n\n## Remediation\n\nAffected\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-72813)\n\nAffected packages:\n\n- `actix-files < 0.6.10`\n\nPatched in:\n\n- `actix-files 0.6.10`\n\nSource: https://osv.dev/vulnerability/GHSA-gcqf-3g44-vc9p","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206976,"id":"CVE-2026-72813","ts":1789749726843,"field":"cvss","old":null,"new":"7.5"},{"seq":206975,"id":"CVE-2026-72813","ts":1789749726843,"field":"severity","old":"medium","new":"high"}]}