Low severity3.3NVD Advisory· Published Sep 9, 2026
CVE-2026-86776
CVE-2026-86776
Description
KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and terminate.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.