VYPR

hfs2

by Wgetnz

CVEs (3)

  • CVE-2026-97360CriSep 24, 2026
    risk 0.65cvss 10.0epss

    HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the shared folder. Attackers can exploit…

  • CVE-2026-97359CriSep 24, 2026
    risk 0.65cvss 10.0epss

    HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attackers can craft a filename containing a…

  • CVE-2026-97362HigSep 24, 2026
    risk 0.42cvss 7.5epss

    HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop,…