CVE-2026-72813High· 7.5▾ TwilightA flaw was found in actix-files. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by sending a GET request with an empty Range header when the application is configured to abort on panic. This can lead to th…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
Last analysed / modified upstream
— → 7.5
medium → high
A flaw was found in actix-files. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by sending a GET request with an empty Range header when the application is configured to abort on panic. This can lead to the application crashing on demand.
actix-files: actix-files: Denial of Service via empty Range header in GET requests — rated Important by Red Hat. Released 2026-08-14, updated 2026-09-18.
Affected:
No fix planned:
Affected
Workarounds / mitigations:
Affected packages:
actix-files < 0.6.10Patched in:
actix-files 0.6.10Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72814Medium· 5.3actix-files: actix-files: Information Disclosure via relative path traversal (CVE-2026-72814)
CVE-2025-58188Mediumcrypto/x509: golang: Panic when validating certificates with DSA public keys in crypto/x509 (CVE-2025-58188)
CVE-2026-41523High· 7.5vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)
CVE-2026-89716Medium· 4.4kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation (CVE-2026-89716)
CVE-2026-89727High· 7.0kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID (CVE-2026-89727)
CVE-2026-45819High· 7.5baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.