VYPR

Kdbx Header Size Mirage Poc

by Ksecur1ty

CVEs (1)

  • CVE-2026-86776LowSep 9, 2026
    risk 0.21cvss 3.3epss

    KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the…