{"id":"CVE-2026-97362","title":"HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request","summary":"HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung ser…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"rejetto","product":"hfs2","affected":["hfs2 >= 2.0.0 <= 2.4.0"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:08:55.030","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97362","references":[{"url":"https://github.com/wgetnz/hfs2/blob/master/advisories/hfs2-getini-infinite-loop-dos/README.md","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hfs2-unauthenticated-denial-of-service-via-hung-serving-thread","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-24T15:32:26.283903Z"},"ingestedAt":"2026-09-24T15:45:56.650Z","slug":"CVE-2026-97362","body":"## Overview\n\nHFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":210285,"id":"CVE-2026-97362","ts":1790268475856,"field":"exploit_available","old":"false","new":"true"}]}