---
id: CVE-2026-72838
title: >-
  FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length
  in the TUS resumable-upload PATCH endpoint, allowing authenticated users to
  write arbitrary data to disk
summary: >-
  FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length
  in the TUS resumable-upload PATCH endpoint, allowing authenticated users to
  write arbitrary data to disk. Attackers can send oversized request bodies that
  exc…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
published: '2026-08-14'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72838'
references:
  - url: >-
      https://github.com/filebrowser/filebrowser/commit/4daddec6f200b03a721197d8c0b4b652c994894e
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-ffv3-7h97-993q
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/filebrowser-before-disk-exhaustion-via-tus-upload
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.0053
epssPercentile: 0.42425
ingestedAt: '2026-09-08T21:11:12.278Z'
---

## Overview

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service unavailability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
