Description
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken generated by the FileUpload component. An attacker can repeatedly upload files and fill application storage, causing denial of service. DotvvmConfiguration.Security.AuthorizeFileUpload can additionally restrict which users may upload files. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unrestricted file upload
Action: Immediate Patch
AI Analysis

Impact

DotVVM exposes a file upload endpoint known as DotvvmFileUploadMiddleware that accepts files without first validating an X-DotVVM-UploadToken. This omission allows an unauthenticated attacker to repeatedly upload arbitrary files, rapidly filling the configured storage location. The abuse does not provide code execution or confidential data disclosure, but it can exhaust disk space or application resources, resulting in a denial of service. The flaw aligns with CWE-434: Unrestricted Upload of File with Dangerous Type.

Affected Systems

Any DotVVM installation prior to version 4.2.11, 4.3.15, or 5.0.0-preview09-final is affected when file upload storage is enabled. The framework configuration allows the upload feature to be scoped, but unless the security guard DotvvmConfiguration.Security.AuthorizeFileUpload is enforced, all users—including unauthenticated ones—can exploit the upload path.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; the EPSS score is 0.0044, indicating a low but non‑zero probability of exploitation. Because the vulnerability does not allow code execution or privilege escalation, it is not listed in CISA's KEV catalog. Nonetheless, attackers with network access to the application can use the exposed endpoint to saturate storage and trigger a denial of service. The attack path requires only an HTTP request to the upload middleware and does not rely on authenticated credentials.

Generated by OpenCVE AI on September 20, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DotVVM to a fixed release: 4.2.11, 4.3.15, or 5.0.0-preview09-final or later.
  • If an upgrade cannot be performed immediately, configure DotvvmConfiguration.Security.AuthorizeFileUpload to restrict uploads to authorized users, or disable the upload middleware entirely by removing the relevant configuration entry.
  • Implement storage limits or rotate/deallocate the upload directory to prevent the storage from filling, and monitor disk usage to detect precursory signs of a denial-of-service attempt.

Generated by OpenCVE AI on September 20, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Riganti
Riganti dotvvm
Vendors & Products Riganti
Riganti dotvvm

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken generated by the FileUpload component. An attacker can repeatedly upload files and fill application storage, causing denial of service. DotvvmConfiguration.Security.AuthorizeFileUpload can additionally restrict which users may upload files. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Title DotVVM: Unrestricted file upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:56:36.035Z

Reserved: 2026-06-24T18:49:56.209Z

Link: CVE-2026-57581

cve-icon Vulnrichment

Updated: 2026-09-16T15:56:17.871Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:58.567

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-57581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type