---
id: CVE-2026-86776
title: >-
  KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes
  before memory allocation in the ReadHeaderField function
summary: >-
  KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes
  before memory allocation in the ReadHeaderField function. Attackers can craft
  a malicious KDBX file declaring excessive header field lengths to trigger
  allocat…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-789
vendor: KeePass
product: KeePass
affected:
  - KeePass >= 2.35 <= 2.61.1
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T19:58:20.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86776'
references:
  - url: 'https://github.com/KSecur1ty/KDBX-Header-Size-Mirage-POC'
    label: disclosure@vulncheck.com
  - url: 'https://keepass.info/'
    label: disclosure@vulncheck.com
  - url: 'https://keepass.info/download.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/keepass-2.35-through-2.61.1-memory-exhaustion-via-kdbx-header-field-size
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T13:48:59.785045Z'
ingestedAt: '2026-09-10T19:31:12.546Z'
epss: 0.00168
epssPercentile: 0.05314
---

## Overview

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
