GHSA-5r36-v86r-vm5xMediumCVSS 3.3

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory...

Published
September 9, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.

🔗 References (6)