CVE-2026-32759Integer Overflow or Wraparound in Filebrowser

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 59.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMar 26

Description

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, the TUS resumable upload handler parses the Upload-Length header as a signed 64-bit integer without validating that the value is non-negative, allowing an authenticated user to supply a negative value that instantly satisfies the upload completion condition upon the first PATCH request. This causes the server to fire after_upload e

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L

Affected Packages3 packages

🔴Vulnerability Details

4
OSV
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely in github.com/filebrowser/filebrowser2026-03-26
CVEList
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely2026-03-19
GHSA
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely2026-03-16
OSV
File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely2026-03-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-32759 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-32759 — Integer Overflow or Wraparound | cvebase