---
id: CVE-2026-82235
title: >-
  filebrowser through 2.63.23 fails to validate named pipes in directory archive
  and public download handlers, allowing attackers to trigger blocking open
  syscalls
summary: >-
  filebrowser through 2.63.23 fails to validate named pipes in directory archive
  and public download handlers, allowing attackers to trigger blocking open
  syscalls. Authenticated users or anonymous visitors with public share links
  can repe…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
published: '2026-08-28'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:34:34.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82235'
references:
  - url: 'https://github.com/filebrowser/filebrowser/commit/586d198d'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/filebrowser/filebrowser/security/advisories/GHSA-8q5j-8wcr-8v2v
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/filebrowser-through-2.63.23-denial-of-service-via-named-pipes
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00515
epssPercentile: 0.4143
ingestedAt: '2026-09-24T20:51:40.237Z'
---

## Overview

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named pipes to pin server goroutines and exhaust connection resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
