Impact
DotVVM exposes a file upload endpoint known as DotvvmFileUploadMiddleware that accepts files without first validating an X-DotVVM-UploadToken. This omission allows an unauthenticated attacker to repeatedly upload arbitrary files, rapidly filling the configured storage location. The abuse does not provide code execution or confidential data disclosure, but it can exhaust disk space or application resources, resulting in a denial of service. The flaw aligns with CWE-434: Unrestricted Upload of File with Dangerous Type.
Affected Systems
Any DotVVM installation prior to version 4.2.11, 4.3.15, or 5.0.0-preview09-final is affected when file upload storage is enabled. The framework configuration allows the upload feature to be scoped, but unless the security guard DotvvmConfiguration.Security.AuthorizeFileUpload is enforced, all users—including unauthenticated ones—can exploit the upload path.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is 0.0044, indicating a low but non‑zero probability of exploitation. Because the vulnerability does not allow code execution or privilege escalation, it is not listed in CISA's KEV catalog. Nonetheless, attackers with network access to the application can use the exposed endpoint to saturate storage and trigger a denial of service. The attack path requires only an HTTP request to the upload middleware and does not rely on authenticated credentials.
OpenCVE Enrichment