Impact
File Browser through version 2.63.23 contains a flaw in the subtitle conversion endpoint where the service loads an entire subtitle file into memory without imposing any size limits. An attacker who can authenticate and request a conversion of a large ".srt", ".ass", or ".ssa" file can cause the server to consume all available memory, leading to a denial of service for the application.
Affected Systems
The vulnerability affects any instance of File Browser running version 2.63.23 or earlier. This includes all builds released under the "filebrowser:filebrowser" vendor/product identification. The issue is tied to that product’s subtitle conversion handler and is not limited to a single installation or deployment scenario.
Risk and Exploitability
With a CVSS score of 7.1, the flaw presents a moderate-to-high severity risk to availability. The EPSS score is not reported, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no currently known widespread exploitation. However, the flaw requires the attacker to have download permissions on the system, meaning that once such privileges are obtained – either through legitimate access or compromise – the attacker can trigger the memory exhaustion by sending multiple concurrent conversion requests users, an internal or remote actor could abuse the endpoint to bring the web server or API service to a halt, disrupting service for legitimate users.
OpenCVE Enrichment