Impact
The vulnerability arises because filebrowser versions up to 2.63.23 do not validate named pipes in directory archive and public download handlers. An attacker can trigger blocking open system calls by requesting archives that contain named pipe entries, causing goroutine hang and exhausting connection resources, which leads to denial of service for legitimate users.
Affected Systems
The affected product is the filebrowser application. All releases up to and including version 2.63.23 are vulnerable. Any installation running an unpatched instance may be compromised, regardless of authentication level or public sharing settings.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity issue. EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog, so the current risk of exploitation is uncertain. The most feasible attack vectors are likely remote HTTP requests to the archive and download endpoints; both authenticated users and anonymous visitors with public share links can exploit the flaw. Successful exploitation results in goroutine exhaustion and a complete denial of service.
OpenCVE Enrichment