KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate. | |
| Title | KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size | |
| First Time appeared |
Keepass
Keepass keepass |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:2.3:a:keepass:keepass:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Keepass
Keepass keepass |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T10:07:26.502Z
Reserved: 2026-09-08T11:35:02.617Z
Link: CVE-2026-86776
No data.
Status : Received
Published: 2026-09-09T10:22:33.970
Modified: 2026-09-09T10:22:33.970
Link: CVE-2026-86776
No data.
OpenCVE Enrichment
Updated: 2026-09-09T12:00:08Z
Weaknesses