CVE-2026-90928
largeAuthenticated Memory Exhaustion DoS in File Browser Subtitle Conversion
File Browser through 2.63.23 contains an uncontrolled resource consumption flaw (CWE-400) in its subtitle conversion endpoint, which loads entire subtitle files into memory without any size limit. An authenticated attacker holding download permission can trigger the bug by requesting conversion of a large .srt, .ass, or .ssa file, and then issue concurrent conversion requests to exhaust server memory. Successful exploitation degrades or crashes the File Browser service (and potentially the host), causing denial of service with no impact on confidentiality or integrity. Any deployment running version 2.63.23 or earlier that grants accounts download permission is affected. No public proof of concept is known and the issue is not in CISA's KEV, so exploitation in the wild is not currently evidenced.
What to do: Upgrade File Browser to a release newer than 2.63.23 as soon as a fixed build is available. In the meantime, limit which accounts hold download permission, and enforce request-rate limits and file/body size caps at a reverse proxy or gateway to blunt concurrent conversion requests. Monitor server memory and logs for repeated conversion attempts against large .srt/.ass/.ssa files as an indicator of abuse.
| File Browser project (filebrowser/filebrowser) File Browser | through 2.63.23 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through concurrent requests, causing denial of service.
- Weakness
- CWE-400
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.